SAP security note 1433736, "Security Note: Automatic execution of BPM task attachments", released on 09.03.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
Certain types of attachments to BPM tasks and processes are recognized by the browser and automatically executed upon download, e.g., JavaScript files. This creates a potential risk of executing malicious active content. Since BPM as a platform is not intended for use with open user groups (i.e., anonymous users), the risk is rated low.
Solution
Upgrade to SAP NW BPM 7.20 or a subsequent version.
Reason and prerequisites
The issue was caused by an incorrect Content-Disposition HTTP header in the response of requests for downloading attachments.
Full note on SAP: SAP Support Launchpad note 1433736
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



