SAP NetWeaver 'ABAD0_DELETE_DERIVATION_TABLE' Function SQL Injection Vulnerability
BID:62147
Info
SAP NetWeaver 'ABAD0_DELETE_DERIVATION_TABLE' Function SQL Injection Vulnerability
| Bugtraq ID: | 62147 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 20 2013 12:00AM |
| Updated: | Aug 20 2013 12:00AM |
| Credit: | Nikolay Mescherin of ERPScan |
| Vulnerable: |
SAP NetWeaver 7.30 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver 'ABAD0_DELETE_DERIVATION_TABLE' Function SQL Injection Vulnerability
SAP NetWeaver is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
SAP NetWeaver 7.30 is vulnerable; other versions may also be affected.
SAP NetWeaver is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
SAP NetWeaver 7.30 is vulnerable; other versions may also be affected.
Exploit / POC
SAP NetWeaver 'ABAD0_DELETE_DERIVATION_TABLE' Function SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
References
SAP NetWeaver 'ABAD0_DELETE_DERIVATION_TABLE' Function SQL Injection Vulnerability
References:
References:
- SAP Homepage (SAP)