SAP security note 1865302, "Code Injection Vulnerability in CO-PA". Below are the symptom and SAP recommended solution.
Description
Symptom
CO-PA contains code that permits the execution of arbitrary program code of the user’s choice. An attacker can control the behavior of the system or potentially escalate privileges by executing malicious code without having legitimate credentials.
Solution
Implement the recommended code provided in the security note to mitigate the vulnerability.
Reason and prerequisites
The program code allows defining and executing user-defined code that changes the system’s behavior. A valid and authenticated user is required. Depending on the code, the user can inject and run their own code.
Full note on SAP: SAP Support Launchpad note 1865302
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
