High priority
SAP security note 2006974, “Code Injection Vulnerability in PP-PI-CFB”, is a program error note released on June 10, 2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
PP-PI-CFB contains code that permits the execution of arbitrary program code of the user’s choice. An attacker can control the system’s behavior or potentially escalate privileges by executing malicious code without having legitimate credentials.
Solution
Implement the attached correction instructions. Additionally, review the BAdI documentation and implement the BAdI to allow the usage of your own reports for the overview form printing.
Affected components
- SAP_APPL: 606, 616, 617
Full note on SAP: SAP Support Launchpad note 2006974
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




