SAP security note 1781594, "Code injection vulnerability in component BC-SRV-ALV". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Component BC-SRV-ALV contains code that permits the execution of arbitrary program code of the user’s choice. An attacker can control the behavior of the system or potentially escalate privileges by executing malicious code without having legitimate credentials. This vulnerability allows injecting and running malicious code, obtaining unauthorized information, modifying or deleting data, altering system output, creating users with higher privileges, or performing denial of service attacks.
Solution
The affected function is disabled in the current version. To fully address the vulnerability, please implement the correction instructions provided by SAP. You can access the correction instructions here.
Additionally, ensure that your system is updated with the latest support packages corresponding to your software component version:
- SAPKIPYJ6P for PI_BASIS 2005_1_640
- SAPKIPYJ7R for PI_BASIS 2005_1_700
- SAPKIPYL16 for PI_BASIS 2006_1_640
- SAPKIPYM19 for PI_BASIS 2006_1_700
- SAPKIPYN16 for PI_BASIS 2006_1_710
- SAPK-70113INPIBASIS for PI_BASIS 701
- SAPK-70213INPIBASIS for PI_BASIS 702
- SAPK-71111INPIBASIS for PI_BASIS 711
- SAPK-72008INPIBASIS for PI_BASIS 720
- SAPK-73009INPIBASIS for PI_BASIS 730
- SAPK-73107INPIBASIS for PI_BASIS 731
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- PI_BASIS 2005_1_640 to 2005_1_700
- PI_BASIS 2006_1_640 to 2006_1_710
- PI_BASIS 701 to 702
- PI_BASIS 711 to 731
Full note on SAP: SAP Support Launchpad note 1781594
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




