SAP Security Note
HotNews
SAP security note 2306709, "Code Injection vulnerability in Documentation and Translation Tools", is a program error note released on 14.06.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BC-DOC-TER allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Some well-known impacts of Code Injection vulnerability are:
- Unauthorized execution of commands
- Sensitive information disclosure
- Denial of Service
Solution
As a fix, affected program code lines are deleted as the code lines were obsolete. Implement the correction instructions referenced by this SAP Note.
CVSS
Score 9.1 Vector: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected components
- SAP_BASIS (731, 740, 750, 764)
Full note on SAP: SAP Support Launchpad note 2306709
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
