Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1482450-2)
SAP Support Packages
(SAPKU70102)
Описание
The problem is caused by an SQL injection vulnerability. The code composes an SQL statement including strings that can be altered by a malicious user. The manipulated SQL statement can then be used to retrieve additional information from the database or to potentially modify it.
Как исправить
Apply template ID input validation.
Please implement the attached correction instructions.
This fix is valid for CRM 7.01.
------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 701 Until SAPKU70101 |
------------------------------------------------------------------------
1. In SAP GUI, launch transaction SE91
2. Input 'CRM_MASS' in field 'Message Class'
3. Click on button 'Change'
4. Locate message '590'
5. Input 'Template ID is invalid' in column 'Message shorttext'
6. Click on button 'Save' to save the change
Please implement the attached correction instructions.
This fix is valid for CRM 7.01.
------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 701 Until SAPKU70101 |
------------------------------------------------------------------------
1. In SAP GUI, launch transaction SE91
2. Input 'CRM_MASS' in field 'Message Class'
3. Click on button 'Change'
4. Locate message '590'
5. Input 'Template ID is invalid' in column 'Message shorttext'
6. Click on button 'Save' to save the change
Ссылки