SAP Security Note
Medium priority
SAP security note 2272676, "Spreadsheet Formula Injection in FPM List UIBB ATS/FPM Tree UIBB/WD ALV", is a program error note released on 26.11.2018. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Security Note 2272676 addresses a vulnerability related to Spreadsheet Formula Injection in components such as FPM List UIBB ATS, FPM Tree UIBB, and WD ALV. This issue allows attackers to embed malicious formulas in exported spreadsheet files, which can execute harmful code when opened by users in programs like Microsoft Excel.
When exporting data using the Export To Spreadsheet function in either CSV or Office Open XML (Microsoft Excel) formats, attackers can manipulate the data to include formulas that execute upon opening the file. In the case of CSV files, Microsoft Excel displays a warning about potential security concerns, and if the user enables automatic update of links, the embedded malicious formulas execute automatically. For Office Open XML formats, additional steps are required for the formulas to execute, including user interaction.
Solution
To mitigate this vulnerability, you need to import the relevant support packages as listed in the note. These packages protect all cell contents against potentially malicious formulas. Additionally, if not already implemented, apply SAP Note 2416832 to further secure your system against similar threats.
CVSS
Score 5.4 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Full note on SAP: SAP Support Launchpad note 2272676
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




