SAP security note 1873131, "Code injection vulnerability in MM-IM". Below are the symptom and SAP recommended solution.
Description
Symptom
MM-IM contains code that permits the execution of arbitrary program code of the user’s choice. An attacker can control the system’s behavior or escalate privileges by executing malicious code without having their own legitimate credentials.
Solution
Corrections are delivered with the assigned Support Package.
For an advanced correction, see the correction instructions.
Reason and prerequisites
The program code allows defining and executing user-defined code that alters system behavior. A valid and authenticated user is required. Depending on the code, the user can inject and run their own code, modify, and delete data.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1873131
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
