Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 2319506
was released on
09.08.2016 and deals with
"SQL injection vulnerability in Database Monitors for Oracle" within Oracle.
We advice you to follow the instructions, to resolve
sql injection
with a
high potential for exploitation
in component BC-CCM-MON-ORA.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
The function modules STUO_GET_ORA_SYS_TABLE and STUO_GET_ORA_SYS_TABLE_2 allow an authenticated attacker to inject arbitrary SQL statements which may lead to sensitive data being leaked or data being improperly manipulated or the system brought to standstill.Solution
Checks have been added before executing the SQL statements to prohibit exploiting the vulnerability.
The advisory is valid for
- SAP_BASIS 700-702 66
- SAP_BASIS 710-711 21
- SAP_BASIS 730 34
- SAP_BASIS 731 78
- SAP_BASIS 740 81
- SAP_BASIS 750 78
- 9.9 [CVE-2023-0016] SQL Injection vulnerability in SAP Business Planning and Consolidation MS
- 9.9 [CVE-2021-38176] SQL Injection vulnerability in SAP NZDT Mapping Table Framework
- 9.8 [CVE-2023-37483] Multiple Vulnerabilities in SAP PowerDesigner
- 9.1 [CVE-2021-33701] SQL Injection vulnerability in SAP NZDT Row Count Reconciliation
- 8.8 [CVE-2021-42064] SQL Injection vulnerability in SAP Commerce