SAP Security Note
High priority
SAP security note 1675511, "code injection vulnerability in module editor for BA70-80", is a note released on 12.06.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses a code injection vulnerability in the module editor of the SAP Financial Services module. An attacker with developer authorization (object S_DEVELOP) can execute arbitrary ABAP code, potentially leading to system behavior manipulation or privilege escalation without having legitimate credentials.
Solution
Please install the attached correction or the corresponding support package.
CVSS
Score 0
References
- SAP Note 1688518 – code injection vulnerability in module editor
- SAP Note 1688294 – New step types for SDL Primary Objects
Affected components
- FSAPPL 300
- FSAPPL 400
Full note on SAP: SAP Support Launchpad note 1675511
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
