Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1520781-5)
SAP Support Packages
(SAPK-60019INISOIL, SAPK-60209INISOIL, SAPK-60308INISOIL, SAPK-60409INISPRA, SAPK-60503INISPRA)
Описание
The program code contains a possibility to define and execute user-defined code that changes the behavior of the system. A valid and authenticated user is required.
Depending on the code, the user can:
-inject and run their own code,
-obtain additional information that should not be displayed,
-modify data, delete data,
-modify the output of the system,
-create new users with higher privileges,
-perform a denial of service attack.
There is SQL injection vulnerability too. The code composes an SQL statement that contains strings that can be altered by a malicious user. The manipulated SQL statement can then be used to retrieve additional data from the database, or to modify the data.
Depending on the code, the user can:
-inject and run their own code,
-obtain additional information that should not be displayed,
-modify data, delete data,
-modify the output of the system,
-create new users with higher privileges,
-perform a denial of service attack.
There is SQL injection vulnerability too. The code composes an SQL statement that contains strings that can be altered by a malicious user. The manipulated SQL statement can then be used to retrieve additional data from the database, or to modify the data.
Как исправить
Applying the note will protect the application from the following vulnerability:-
1) Dynamic SQL Injection
2) Code injection
Hence applying the note will prevent the PRA application from the above mentioned security vulnerability
1) Dynamic SQL Injection
2) Code injection
Hence applying the note will prevent the PRA application from the above mentioned security vulnerability
Ссылки