SAP Security Note
High priority
SAP security note 2552318, "Update 1 to Security Note 2376081", is a note released on April 10, 2018. Below are the symptom and SAP recommended solution.
Description
Symptom
This SAP Note supplements the corrections provided in Security Note 2376081. Additional code changes have been made to completely solve the vulnerability.
Solution
In the export to Excel mechanism, the entire input stream received from Visual Composer is now being checked for Code Injection vulnerabilities.
Reason and prerequisites
The correction instructions from Security Note 2376081 must be supplemented.
CVSS
Score 7.4 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
References
Full note on SAP: SAP Support Launchpad note 2552318
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
