Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Spreadsheet Formula Injection in FPM List UIBB ATS/FPM Tree UIBB/WD ALV, SAP security note 2272676

SAP Note 2272676
SAP Security Note
Medium priority

SAP security note 2272676, "Spreadsheet Formula Injection in FPM List UIBB ATS/FPM Tree UIBB/WD ALV", is a program error note released on 26.11.2018. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Web Dynpro > Configurable Component > List Viewer > ALV for ABAP
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on26.11.2018

Description

Symptom

SAP Security Note 2272676 addresses a vulnerability related to Spreadsheet Formula Injection in components such as FPM List UIBB ATS, FPM Tree UIBB, and WD ALV. This issue allows attackers to embed malicious formulas in exported spreadsheet files, which can execute harmful code when opened by users in programs like Microsoft Excel.

When exporting data using the Export To Spreadsheet function in either CSV or Office Open XML (Microsoft Excel) formats, attackers can manipulate the data to include formulas that execute upon opening the file. In the case of CSV files, Microsoft Excel displays a warning about potential security concerns, and if the user enables automatic update of links, the embedded malicious formulas execute automatically. For Office Open XML formats, additional steps are required for the formulas to execute, including user interaction.

Solution

To mitigate this vulnerability, you need to import the relevant support packages as listed in the note. These packages protect all cell contents against potentially malicious formulas. Additionally, if not already implemented, apply SAP Note 2416832 to further secure your system against similar threats.

CVSS

Score 5.4 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2272676

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More