Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in ABAP, SAP security note 2198580

SAP Note 2198580
SAP Security Note
High priority

SAP security note 2198580, “Code injection vulnerability in ABAP”, is a note released on November 10, 2015. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > ABAP Runtime Environment – ABAP Language Issues Only > Syntax, Compiler, Runtime
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onNovember 10, 2015

Description

Symptom

ABAP contains code that permits the execution of arbitrary program code of the developer’s choice. An attacker can therefore control the behavior of the system or potentially escalate privileges by executing malicious code without having their own legitimate credentials.

Solution

This correction disables the comment *@#. Please apply the kernel patch mentioned in this SAP Note.

Reason and prerequisites

The program code allows defining and executing developer-defined code that changes the system behavior. A valid and authenticated developer is required. Depending on the code, the developer can inject code that is hidden to other users.

Affected components

  • SAP KERNEL 7.45 64-BIT UNICODE
  • SAP KERNEL 7.22 64-BIT
  • SAP KERNEL 7.22 64-BIT UNICODE
  • SAP KERNEL 7.42 64-BIT UNICODE

Full note on SAP: SAP Support Launchpad note 2198580

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More