SAP Security Note
High priority
SAP security note 1499627, “Executing any source code using template report”, is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
By making specific entries in a table, an attacker can generate programs with harmful source code. The tables belong to the component CO-OM-ABC-F.
Solution
Navigate to the table maintenance for the tables COTPLFS and COTPL, and change the setting on the Delivery and Maintenance tab page from Display/Maintenance Allowed to Display/Maintenance Allowed with Restrictions, or import the relevant Support Package.
Then call transactions SE16 and SE16N for the tables COTPL and COTPLFS. It should no longer be possible to add or change entries.
Reason and prerequisites
The program code allows source code that can be freely determined to be added and executed, enabling an attacker to control the system response. Valid logon information is required for this.
The relevant program code must be stored in a database table. Therefore, an attacker requires authorization for transaction SE16 or SE16N as well as change authorization for the authorization object S_TABU_DIS.
With these authorizations, it is possible to make new entries in the tables because you have selected the "Display/Maintenance Allowed" option in the "Delivery and Maintenance" settings.
Full note on SAP: SAP Support Launchpad note 1499627
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
