SAP Security Note
Medium priority
SAP security note 1537213, “Code injection vulnerability in BC-MOB-DOE-GEN”, is a program error note released on 09.02.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
BC-MOB-DOE-GEN contains code that permits the execution of arbitrary program code of the user’s choice. A malicious user can therefore control the behavior of the system, or can potentially escalate privileges by executing malicious code, without having their own legitimate credentials.
Solution
These statements are removed.
- Apply SP12 if you are on WebAs 7.10
- or apply SP07 if you are on WebAs 7.11
Reason and prerequisites
The program code contains a possibility to define and execute user-defined code that changes the behavior of the system. Depending on the code, the user can:
- Inject and run their own code
- Obtain additional information that should not be displayed
- Modify data, delete data
- Modify the output of the system
- Create new users with higher privileges
- Perform a denial of service attack
Pre-requisite: you are on SP08 – SP11 of WebAs 7.10, or you are on a SP lower than SP07 of WebAs 7.11.
Full note on SAP: SAP Support Launchpad note 1537213
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
