SAP security note 1584170, "Code injection vulnerability in component Bank Analyzer", released on June 14, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Allows execution of arbitrary code. Malicious users can control system behavior or escalate privileges without legitimate credentials.
Solution
To address this vulnerability, implement the provided correction instructions or apply the relevant support packages.
References
Affected components
- FSAPPL versions 200 and 300
- BANK-ALYZE version 50
Full note on SAP: SAP Support Launchpad note 1584170
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
