Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in PM-EQM, SAP security note 1492145

SAP Note 1492145SAP Security NoteMedium priority

SAP security note 1492145, "Code Injection Vulnerability in PM-EQM", is released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentPlant Maintenance > Equipment and Technical Objects (PM-EQM)
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

PM-EQM contains code that permits the execution of arbitrary program code of the user’s choice. A malicious user can therefore control the behavior of the system or potentially escalate privileges by executing malicious code without having their own legitimate credentials.

The vulnerability allows:

  • Injection and execution of unauthorized code
  • Modification or deletion of data
  • Creation of new users with higher privileges
  • Potential denial of service attacks

Solution

Implement the correction instructions provided in this security note to mitigate the vulnerability.

Reason and prerequisites

The program code allows defining and executing user-defined code that changes the system’s behavior. Specific prerequisites include [additional prerequisites if available].

Affected components

  • SAP_APPL 31I
  • SAP_APPL 40B
  • SAP_APPL 45B
  • SAP_APPL 46B
  • SAP_APPL 46C
  • SAP_APPL 470
  • SAP_APPL 500
  • SAP_APPL 600
  • SAP_APPL 602
  • SAP_APPL 603
  • SAP_APPL 604
  • SAP_APPL 605

Full note on SAP: SAP Support Launchpad note 1492145

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More