Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1511877-3)
SAP Support Packages
(SAPK-70410INBICONT, SAPK-70502INBICONT)
Описание
SPM1.0 code contains code which fails to correctly validate the path a user-submitted file is written to. Through this, an attacker can potentially overwrite data on the remote system.
The second issue is caused by an SQL injection vulnerability. The code composes an SQL statement including strings that can be altered by a malicious user. The manipulated SQL statement can then be used to modify information in the database.
The second issue is caused by an SQL injection vulnerability. The code composes an SQL statement including strings that can be altered by a malicious user. The manipulated SQL statement can then be used to modify information in the database.
Как исправить
This code is obsolete for SPM2.0 onwards. Please apply the attached correction instruction to comment out the obsolete code.
Ссылки