SAP security note 1509681, "Inserting ABAP code in SAP Payment Engine", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The SAP Payment Engine contains ABAP code that may enable an attacker to introduce their own code and execute it.
Solution
Implement the source code corrections manually.
Use transaction SE38 to delete the report /PE4/PE_PP_IF_SHOW_REP_PARAMS.
Reason and prerequisites
The program contains statements that enable a user to execute their own code, resulting in a changed system response. The user must be logged on with valid system access and have authorization to execute reports. Depending on the code inserted, additional information access may be required, which is not guaranteed. Furthermore, the user may change or delete data, manipulate system output, or create new users with increased privileges. Additionally, the availability of the system is endangered.
Affected components
- PAY-ENGINE: Version 300
Full note on SAP: SAP Support Launchpad note 1509681
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
