SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD0_DELETE_DERIVATION_TABLE."
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1029018 | vdb entry |
https://erpscan.io/advisories/dsecrg-13-016-sap-netweaver-abad0_delete_derivation_table/ | |
http://secunia.com/advisories/54702 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/62147 | vdb entry |
https://service.sap.com/sap/support/notes/1840249 | |
http://scn.sap.com/docs/DOC-8218 | |
http://osvdb.org/96900 | vdb entry |