SAP security note 2025931, “Potential remote code execution in BC-SEC”, is a program error note released on August 12, 2014. Below is the security information published by SAP for this note.
Description
Symptom
An attacker can exploit BC-SEC to gain complete control of the product, including viewing, changing, or deleting data.
Reason and prerequisites
A buffer overflow vulnerability exists in BC-SEC. This allows an attacker to inject code into the working memory, which is executed by the application, or cause the application to terminate. To exploit this vulnerability, an attacker must have the ability to create and run or modify ABAP source code. No known existing interfaces directly expose the vulnerability.
Solution
Apply the relevant kernel patch provided by SAP. You can download the patch via the Download for SNOTE or view the PDF Version.
Affected components
This security note applies to the following SAP KERNEL components:
- KRNL32NUC
- KRNL32UC
- KRNL64NUC
- KRNL64UC
- KERNEL
Supported versions include 7.20, 7.21, 7.38, 7.40, 7.41, 7.42, and 8.04 across 32-bit, 64-bit, and Unicode configurations.
For detailed support package patches, refer to the Support Package Patches page.
Additional information
- Type: SAP Security Note
- Recency: New
- Category: Program error
- Priority: Correction with high priority
- Status: Released for Customer
- Released On: August 12, 2014
Full note on SAP: SAP Support Launchpad note 2025931
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
