SAP security note 1486918, “Code Injection vulnerability in CRM-ACP-APL”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
CRM-ACP-APL contains code that allows the execution of arbitrary program code chosen by the user. A malicious user can control system behavior or potentially escalate privileges by executing malicious code without legitimate credentials.
Solution
Apply the attached correction instructions.
Reason and prerequisites
The program code allows users with full debugging rights to define and execute code, potentially modifying data, deleting data, altering system output, creating users with higher privileges, or performing denial of service attacks. A valid and authenticated user is required.
References
Affected components
- BBPCRM versions: 520, 600, 700, 701
Full note on SAP: SAP Support Launchpad note 1486918
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
