Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in BC-MOB-DOE-GEN, SAP security note 1537213

SAP Note 1537213
SAP Security Note
Medium priority

SAP security note 1537213, “Code injection vulnerability in BC-MOB-DOE-GEN”, is a program error note released on 09.02.2011. Below are the symptom and SAP recommended solution.

ComponentBC-MOB-DOE-GEN
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on09.02.2011
LanguageEnglish

Description

Symptom

BC-MOB-DOE-GEN contains code that permits the execution of arbitrary program code of the user’s choice. A malicious user can therefore control the behavior of the system, or can potentially escalate privileges by executing malicious code, without having their own legitimate credentials.

Solution

These statements are removed.

  • Apply SP12 if you are on WebAs 7.10
  • or apply SP07 if you are on WebAs 7.11

Reason and prerequisites

The program code contains a possibility to define and execute user-defined code that changes the behavior of the system. Depending on the code, the user can:

  • Inject and run their own code
  • Obtain additional information that should not be displayed
  • Modify data, delete data
  • Modify the output of the system
  • Create new users with higher privileges
  • Perform a denial of service attack

Pre-requisite: you are on SP08 – SP11 of WebAs 7.10, or you are on a SP lower than SP07 of WebAs 7.11.

Full note on SAP: SAP Support Launchpad note 1537213

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More