• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1520781

Главная Специалистам База уязвимостей Не установлено обновление Note 1520781

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1520781-5) SAP Support Packages (SAPK-60019INISOIL, SAPK-60209INISOIL, SAPK-60308INISOIL, SAPK-60409INISPRA, SAPK-60503INISPRA)
Описание
The program code contains a possibility to define and execute  user-defined code that changes the behavior of the system. A valid and authenticated user is required.
Depending on the code, the user can:
-inject and run their own code,
-obtain additional information that should not be displayed,
-modify data, delete data,
-modify the output of the system,
-create new users with higher privileges,
-perform a denial of service attack.

There is SQL injection vulnerability too. The code composes an SQL  statement that contains strings that can be altered by a malicious user.  The manipulated SQL statement can then be used to retrieve additional data from the database, or to modify the data.
Как исправить
Applying the note will protect the application from the following vulnerability:-
1) Dynamic SQL Injection
2) Code injection

Hence applying the note will prevent the PRA application from the above mentioned security vulnerability
Ссылки
Не установлено обновление Note 1520462 Не установлено обновление Note 1520840