SAP security note 1537216, “Code Injection Vulnerability in BC-MOB-DOE-WB”. Below are the symptom and SAP recommended solution.
Description
Symptom
BC-MOB-DOE-WB contains code that permits the execution of arbitrary program code of the user’s choice. A malicious user can therefore control the behavior of the system or potentially escalate privileges by executing malicious code without having their own legitimate credentials.
Solution
These statements are removed.
- If you are on WebAs 7.10: apply SP12
- If you are on WebAs 7.11: apply SP07
Reason and prerequisites
The program code includes the ability to define and execute user-defined code that changes the system’s behavior. Depending on the code, the user can:
- Inject and run their own code
- Obtain additional information that should not be displayed
- Modify data, delete data
- Modify the output of the system
- Create new users with higher privileges
- Perform a denial of service attack
Pre-requisite: you are on SP08 – SP11 of WebAs 7.10, or you are on a SP lower than SP07 of WebAs 7.11.
Full note on SAP: SAP Support Launchpad note 1537216
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



