SAP security note 1472498, “Code injection vulnerability in Commodity Pricing.” Below are the symptom and SAP recommended solution.
Description
Symptom
A vulnerability has been identified in the Commodity Pricing program which allows the execution of arbitrary code. This flaw enables a malicious user to control system behavior or escalate privileges by running malicious code without legitimate credentials. Additionally, it is possible to manipulate data in any database table through this program.
Solution
A whitelist will be implemented to ensure that only specified tables can be updated by the Commodity Pricing program after applying the correction. This restricts unauthorized table modifications and mitigates the risk of code injection.
Full note on SAP: SAP Support Launchpad note 1472498
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
