SAP Security Note
High priority
SAP security note 1509807, "Code Injection Vulnerability in IS-PRA", is a program error note released on March 8, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The PRA application contains code that permits the execution of arbitrary program code chosen by the user. A malicious user can manipulate the system's behavior or escalate privileges by executing malicious code without legitimate credentials.
Solution
Apply SAP Note 1509344, which contains the necessary corrections to address the vulnerability described in Note 1509807. Implementing this note will safeguard the PRA application against code injection attacks.
Reason and prerequisites
The vulnerability exists because the program code allows defining and executing user-supplied code, altering the system's behavior. To exploit this, an authenticated user is required. Depending on the injected code, attackers can gain unauthorized access to sensitive information, modify or delete data, alter system outputs, create users with higher privileges, or perform denial of service attacks.
References
Affected components
- IS-PRA 605
Full note on SAP: SAP Support Launchpad note 1509807
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
