Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in BC-MOB-DOE-WB, SAP security note 1537216

SAP Note 1537216

SAP security note 1537216, “Code Injection Vulnerability in BC-MOB-DOE-WB”. Below are the symptom and SAP recommended solution.

Description

Symptom

BC-MOB-DOE-WB contains code that permits the execution of arbitrary program code of the user’s choice. A malicious user can therefore control the behavior of the system or potentially escalate privileges by executing malicious code without having their own legitimate credentials.

Solution

These statements are removed.

  • If you are on WebAs 7.10: apply SP12
  • If you are on WebAs 7.11: apply SP07

Reason and prerequisites

The program code includes the ability to define and execute user-defined code that changes the system’s behavior. Depending on the code, the user can:

  • Inject and run their own code
  • Obtain additional information that should not be displayed
  • Modify data, delete data
  • Modify the output of the system
  • Create new users with higher privileges
  • Perform a denial of service attack

Pre-requisite: you are on SP08 – SP11 of WebAs 7.10, or you are on a SP lower than SP07 of WebAs 7.11.

Full note on SAP: SAP Support Launchpad note 1537216

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More