SAP security note 1492145, "Code Injection Vulnerability in PM-EQM", is released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
PM-EQM contains code that permits the execution of arbitrary program code of the user’s choice. A malicious user can therefore control the behavior of the system or potentially escalate privileges by executing malicious code without having their own legitimate credentials.
The vulnerability allows:
- Injection and execution of unauthorized code
- Modification or deletion of data
- Creation of new users with higher privileges
- Potential denial of service attacks
Solution
Implement the correction instructions provided in this security note to mitigate the vulnerability.
Reason and prerequisites
The program code allows defining and executing user-defined code that changes the system’s behavior. Specific prerequisites include [additional prerequisites if available].
Affected components
- SAP_APPL 31I
- SAP_APPL 40B
- SAP_APPL 45B
- SAP_APPL 46B
- SAP_APPL 46C
- SAP_APPL 470
- SAP_APPL 500
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
Full note on SAP: SAP Support Launchpad note 1492145
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



