Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code Injection vulnerability in CRM-ACP-APL, SAP security note 1486918

SAP Note 1486918

SAP security note 1486918, “Code Injection vulnerability in CRM-ACP-APL”, is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

CRM-ACP-APL contains code that allows the execution of arbitrary program code chosen by the user. A malicious user can control system behavior or potentially escalate privileges by executing malicious code without legitimate credentials.

Solution

Apply the attached correction instructions.

Reason and prerequisites

The program code allows users with full debugging rights to define and execute code, potentially modifying data, deleting data, altering system output, creating users with higher privileges, or performing denial of service attacks. A valid and authenticated user is required.

References

Affected components

  • BBPCRM versions: 520, 600, 700, 701

Full note on SAP: SAP Support Launchpad note 1486918

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More