SAP security note 1482180, "Code Injection Vulnerability in Package S_CM_EXTRACT", released on December 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
The vulnerability exists in the S_CM_EXTRACT package, where the code allows the execution of arbitrary program code defined by the user. This can lead to unauthorized control over the system, data manipulation, deletion, or the creation of users with elevated privileges.
- Inject and execute their own code.
- Access sensitive information.
- Modify or delete data.
- Alter system outputs.
- Perform denial of service attacks.
Solution
The affected code belongs to an obsolete program that is no longer in use. Implementing this security note will comment out the vulnerable code, mitigating the risk.
Implementing this note may affect SAP Note 1696811, which deals with an error in report SAPRCKAPP02_WP "Display of Data Extracts".
Full note on SAP: SAP Support Launchpad note 1482180
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
