Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Injecting ABAP code in transaction GENC, SAP security note 1489098

SAP Note 1489098
SAP Security Note
High priority

SAP security note 1489098, "Injecting ABAP code in transaction GENC", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCross-Application Components > Classification (CA-CL)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

Transaction GENC contains a branch to the ABAP Editor for reports generated in this transaction, which may enable a malicious user to inject and execute program code of the user’s choice.

Solution

By implementing the corrections, transaction GENC is no longer executed in the production environment.

Reason and prerequisites

The program contains instructions that enable a user to execute code of the user’s choice, which changes the system’s behavior. In this case, the user must be logged on to the system with a valid access.

Depending on the code that the user injects, the user may obtain additional information to which no actual access was granted. The user may also be able to modify data, delete data, modify the output of the system, or create new users with higher privileges. The availability of the system is still endangered.

CVSS

Score 0

Affected components

  • SAP_APPL 31I
  • SAP_APPL 40B
  • SAP_APPL 45B
  • SAP_APPL 46B
  • SAP_APPL 46C
  • SAP_APPL 470
  • SAP_APPL 500
  • SAP_APPL 600
  • SAP_APPL 602
  • SAP_APPL 603
  • SAP_APPL 604
  • SAP_APPL 605

Full note on SAP: SAP Support Launchpad note 1489098

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More