Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in Function & Class Builder, SAP security note 1594110

SAP Note 1594110
SAP Security Note
High priority

SAP security note 1594110, “Code Injection Vulnerability in Function & Class Builder”, released on March 13, 2012. Below are the symptom and the affected software components.

PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onMarch 13, 2012

Description

Symptom

SAP has released Security Note 1594110 addressing a critical code injection vulnerability in the ABAP Function Builder and ABAP Class Builder. This vulnerability allows malicious users to execute arbitrary program code, potentially leading to system compromise or privilege escalation without legitimate credentials.

Reason and prerequisites

Ensure that the following SAP Notes are applied before implementing this security note: 506765, 972722, 1058934, 1118533.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

References

Affected components

  • SAP_BASIS: 46B to 802
  • ABAP Workbench
  • Java IDE and Infrastructure
  • Workbench Tools: Editors, Painter, Modeler
  • Function Builder (BC-DWB-TOO-FUB)

Full note on SAP: SAP Support Launchpad note 1594110

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More