Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1487212-2)
SAP Support Packages
(SAPK-21014INRMGMT, SAPK-60208INEAAPPL, SAPK-60307INEAAPPL, SAPK-60408INEAAPPL, SAPK-60502INEAAPPL, SAPKGPAB20, SAPKGPAC24, SAPKGPAD18)
Описание
The problem is caused by an SQL injection vulnerability. The code composes an SQL statement including strings that can be altered by a malicious user. The manipulated SQL statement can then be used to retrieve additional data from the database or modify it.
Как исправить
Implement the source code changes that are described in the advance corrections.
------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component EA-APPL SAP R/3 Enterpr...|
| Release 200 Until SAPKGPAB10 |
------------------------------------------------------------------------
If you have not support package EA-APPL 200 SAPKGPAB11 and SAP_BASIS 620SAPKB62054, execute following steps:
1. Create subroutine 'check_dimension_prop' in include 'LFRML814F01'.
2. Save and activate the change.
------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component EA-APPL SAP R/3 Enterpr...|
| Release 500 Until SAPKGPAC11 |
------------------------------------------------------------------------
If you have not support package EA-APPL 500 SAPKGPAC12 and SAP_BASIS 640 SAPKB64012, execute following steps:
1. Open include 'LRMSA185TOP' using transaction SE38 for change.
2. Deactivate line with constant 'gc_suc_sele_nam' by inserting a star '*' at the beginning of the line.
3. Save and activate the change.
4. Excecute steps 1 - 3 for includes 'LRMSA461TOP', 'LRMSA462TOP' and 'LRMSA463TOP'.
------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component EA-APPL SAP R/3 Enterpr...|
| Release 200 Until SAPKGPAB10 |
------------------------------------------------------------------------
If you have not support package EA-APPL 200 SAPKGPAB11 and SAP_BASIS 620SAPKB62054, execute following steps:
1. Open include 'LRMSA185TOP' using transaction SE38 for change.
2. Deactivate line with constant 'gc_suc_sele_nam' by inserting a star '*' at the beginning of the line.
3. Save and activate the change.
4. Excecute steps 1 - 3 for includes 'LRMSA461TOP', 'LRMSA462TOP' and 'LRMSA463TOP'.
------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component EA-APPL SAP R/3 Enterpr...|
| Release 200 Until SAPKGPAB10 |
------------------------------------------------------------------------
If you have not support package EA-APPL 200 SAPKGPAB11 and SAP_BASIS 620SAPKB62054, execute following steps:
1. Create subroutine 'check_dimension_prop' in include 'LFRML814F01'.
2. Save and activate the change.
------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component EA-APPL SAP R/3 Enterpr...|
| Release 500 Until SAPKGPAC11 |
------------------------------------------------------------------------
If you have not support package EA-APPL 500 SAPKGPAC12 and SAP_BASIS 640 SAPKB64012, execute following steps:
1. Open include 'LRMSA185TOP' using transaction SE38 for change.
2. Deactivate line with constant 'gc_suc_sele_nam' by inserting a star '*' at the beginning of the line.
3. Save and activate the change.
4. Excecute steps 1 - 3 for includes 'LRMSA461TOP', 'LRMSA462TOP' and 'LRMSA463TOP'.
------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component EA-APPL SAP R/3 Enterpr...|
| Release 200 Until SAPKGPAB10 |
------------------------------------------------------------------------
If you have not support package EA-APPL 200 SAPKGPAB11 and SAP_BASIS 620SAPKB62054, execute following steps:
1. Open include 'LRMSA185TOP' using transaction SE38 for change.
2. Deactivate line with constant 'gc_suc_sele_nam' by inserting a star '*' at the beginning of the line.
3. Save and activate the change.
4. Excecute steps 1 - 3 for includes 'LRMSA461TOP', 'LRMSA462TOP' and 'LRMSA463TOP'.
Ссылки