SAP security note 1596867, "BRF+: Rule Processing error and code injection vulnerability", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP Security Note addresses a rule processing error and a code injection vulnerability in BRF+. If this note has already been applied to your system, no further action is required.
- Issue: Rule Processing returns incorrect results, and mishandling of the "`" character allows malicious users to execute arbitrary code.
- Impact: Execution of arbitrary code, control over system behavior, and potential privilege escalation.
Solution
Implement the attached correction provided in the SAP Note.
Reason and prerequisites
Ensure that all prerequisite SAP Notes are applied. Refer to the SAP Note for a complete list of prerequisites.
Affected components
- SAP_BASIS 702
- SAP_BASIS 730
Full note on SAP: SAP Support Launchpad note 1596867
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
