Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in component BC-SRV-ALV, SAP security note 1781594

SAP Note 1781594

SAP security note 1781594, "Code injection vulnerability in component BC-SRV-ALV". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Component BC-SRV-ALV contains code that permits the execution of arbitrary program code of the user’s choice. An attacker can control the behavior of the system or potentially escalate privileges by executing malicious code without having legitimate credentials. This vulnerability allows injecting and running malicious code, obtaining unauthorized information, modifying or deleting data, altering system output, creating users with higher privileges, or performing denial of service attacks.

Solution

The affected function is disabled in the current version. To fully address the vulnerability, please implement the correction instructions provided by SAP. You can access the correction instructions here.

Additionally, ensure that your system is updated with the latest support packages corresponding to your software component version:

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

Affected components

  • PI_BASIS 2005_1_640 to 2005_1_700
  • PI_BASIS 2006_1_640 to 2006_1_710
  • PI_BASIS 701 to 702
  • PI_BASIS 711 to 731

Full note on SAP: SAP Support Launchpad note 1781594

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More