SAP @sap/hdi-deploy Package SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in the SAP @sap/hdi-deploy package. This issue arises because SQL queries are generated dynamically using user input, lacking proper parameterization or the use of prepared statements. If exploited, this vulnerability could allow high-privileged users to modify SELECT statements, thereby affecting the application's confidentiality and availability, although integrity remains unaffected.
Impact
Exploitation of this vulnerability could lead to unauthorized alterations of SQL queries, potentially compromising the application's confidentiality and availability.
Remediation
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
