Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Stored data may be changed or disclosed, SAP security note 1497905

Description

An attacker can change stored data by making specific entries in the report /IBS/MRB_CUST_DUPLICATE.

Available fix and Supported packages

  • EA-FINSERV | 500 | 500
  • EA-FINSERV | 600 | 600
  • EA-FINSERV | 603 | 603
  • EA-FINSERV | 604 | 604
  • EA-FINSERV | 605 | 605
  • EA-FINSERV 603 | SAPK-60307INEAFINSRV |
  • EA-FINSERV 605 | SAPK-60502INEAFINSRV |
  • EA-FINSERV 500 | SAPKGPFC24 |
  • EA-FINSERV 604 | SAPK-60408INEAFINSRV |
  • EA-FINSERV 600 | SAPKGPFD19 |

Affected component

    FS-RBD
    Value Adjustment

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1497905

TAGS

#SQL-injection
#database
#RBD
#value-adjustment
#/IBS/MRB_CUST_DUPLICATE

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,