Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 2660005
was released on
14.08.2018 and deals with
"[CVE-2018-2450] SQL Injection Vulnerability in SAP MaxDB/liveCache" within SAP MaxDB.
We advice you to follow the instructions, to resolve
sql injection (read/write)
with a
high potential for exploitation
in component BC-DB-SDB.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
SAP MaxDB/liveCache allows an authentiacted DBM operator user to read, modify or delete sensitive data from the application schema in the database through SQL injection.Solution
The implicit priviledges of the DBM operator user which allowed him to access the application schemas have been reduced to prohibit this in the future. The change is not done via configuration but MaxDB patch.
- 8.8 [CVE-2020-6241] SQL Injection vulnerability in SAP Adaptive Server Enterprise
- 7.2 [CVE-2020-6253] SQL Injection vulnerability in SAP Adaptive Server Enterprise (Web Services)
- 7.2 Update 1 to Note 2319506
- 5.4 SQL Injection in SAF-T Portugal
- 4.1 [CVE-2023-49581] SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform