SAP security note 1504090, "Code injection vulnerability in SCM-APO-PPS". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SCM-APO-PPS contains code that allows the execution of arbitrary program code chosen by the user. A malicious user can control the system’s behavior or potentially escalate privileges by executing malicious code without legitimate credentials.
Solution
The obsolete code line has been removed. Implement the necessary source code corrections to address the vulnerability.
Reason and prerequisites
The program code allows the definition and execution of user-supplied code, altering the system’s behavior. A valid and authenticated user is required. Depending on the injected code, a user can:
- Inject and run their own code
- Obtain additional sensitive information
- Modify or delete data
- Alter system output
- Create new users with higher privileges
- Perform denial of service attacks
CVSS
Score 0
References
This note refers to
Affected components
- SAP_APO: Versions 30A to 310
- SCM: Versions 400 to 701
Full note on SAP: SAP Support Launchpad note 1504090
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
