Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code Injection vulnerability in Documentation and Translation Tools, SAP security note 2306709

SAP Note 2306709
SAP Security Note
HotNews

SAP security note 2306709, "Code Injection vulnerability in Documentation and Translation Tools", is a program error note released on 14.06.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentTerminology/Glossary
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on14.06.2016
LanguageEnglish

Description

Symptom

BC-DOC-TER allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

Some well-known impacts of Code Injection vulnerability are:

  • Unauthorized execution of commands
  • Sensitive information disclosure
  • Denial of Service

Solution

As a fix, affected program code lines are deleted as the code lines were obsolete. Implement the correction instructions referenced by this SAP Note.

CVSS

Score 9.1 Vector: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected components

  • SAP_BASIS (731, 740, 750, 764)

Full note on SAP: SAP Support Launchpad note 2306709

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More