• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1487212

Главная Специалистам База уязвимостей Не установлено обновление Note 1487212

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1487212-2) SAP Support Packages (SAPK-21014INRMGMT, SAPK-60208INEAAPPL, SAPK-60307INEAAPPL, SAPK-60408INEAAPPL, SAPK-60502INEAAPPL, SAPKGPAB20, SAPKGPAC24, SAPKGPAD18)
Описание
The problem is caused by an SQL injection vulnerability. The code  composes an SQL statement including strings that can be altered by a  malicious user. The manipulated  SQL statement can then be used to  retrieve additional data from the database or modify it.
Как исправить
Implement the source code changes that are described in the advance corrections.




------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component EA-APPL SAP R/3 Enterpr...|
| Release 200 Until SAPKGPAB10 |
------------------------------------------------------------------------

If you have not support package EA-APPL 200 SAPKGPAB11 and SAP_BASIS 620SAPKB62054, execute following steps:
1. Create subroutine 'check_dimension_prop' in include 'LFRML814F01'.
2. Save and activate the change.
------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component EA-APPL SAP R/3 Enterpr...|
| Release 500 Until SAPKGPAC11 |
------------------------------------------------------------------------

If you have not support package EA-APPL 500 SAPKGPAC12 and SAP_BASIS 640 SAPKB64012, execute following steps:
1. Open include 'LRMSA185TOP' using transaction SE38 for change.
2. Deactivate line with constant 'gc_suc_sele_nam' by inserting a star '*' at the beginning of the line.
3. Save and activate the change.
4. Excecute steps 1 - 3 for includes 'LRMSA461TOP', 'LRMSA462TOP' and 'LRMSA463TOP'.
------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component EA-APPL SAP R/3 Enterpr...|
| Release 200 Until SAPKGPAB10 |
------------------------------------------------------------------------

If you have not support package EA-APPL 200 SAPKGPAB11 and SAP_BASIS 620SAPKB62054, execute following steps:
1. Open include 'LRMSA185TOP' using transaction SE38 for change.
2. Deactivate line with constant 'gc_suc_sele_nam' by inserting a star '*' at the beginning of the line.
3. Save and activate the change.
4. Excecute steps 1 - 3 for includes 'LRMSA461TOP', 'LRMSA462TOP' and 'LRMSA463TOP'.
Ссылки