Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized code execution in Edit Locally, SAP security note 1535140

SAP Note 1535140
SAP Security Note
High priority

SAP security note 1535140, "Unauthorized code execution in Edit Locally", is a note released on January 10, 2012. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > Enterprise Portal – Knowledge Management and Collaboration > Content Management > CM User Interface
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onJanuary 10, 2012

Description

Symptom

A malicious user can execute arbitrary code with the Edit Locally component.

Solution

There are no workarounds available for this issue. To resolve it, download and deploy the SCA from the "SP Patch Level" tab page of this SAP note.

Reason and prerequisites

The issue is caused by a DLL loading vulnerability.

Full note on SAP: SAP Support Launchpad note 1535140

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More