Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3275391
was released on
10.01.2023 and deals with
"[CVE-2023-0016] SQL Injection vulnerability in SAP Business Planning and Consolidation MS" within SAP Business Planning and Consolidation.
We advice you to follow the instructions, to resolve
sql injection
with a
hot news potential for exploitation
in component EPM-BPC-MS.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
SAP Business Planning and Consolidation MS allow an unauthorized attacker to execute crafted database queries.Solution
SAP Business Planning and Consolidation MS now screens for SQL injection and prevents this type of attack
The advisory is valid for
- CPM_BPC_SMS 800
- CPM_BPC_SMS 810
- 9.9 [CVE-2021-38176] SQL Injection vulnerability in SAP NZDT Mapping Table Framework
- 9.8 [CVE-2023-37483] Multiple Vulnerabilities in SAP PowerDesigner
- 9.1 [CVE-2021-33701] SQL Injection vulnerability in SAP NZDT Row Count Reconciliation
- 8.8 [CVE-2021-42064] SQL Injection vulnerability in SAP Commerce
- 7.2 SQL injection vulnerability in Database Monitors for Oracle