SAP security note 1450128, "Code injection vulnerability in ECC and SAP R/3". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP R/3 4.6, Enterprise R/3 4.7, ECC 5.00, ECC 6.00 – 6.04 contain code which allows execution of arbitrary program code of the user’s choice. A malicious user can therefore control the behavior of the system or potentially escalate privileges by executing malicious code without legitimate credentials.
Solution
Apply the attached correction instructions or implement the HR support packages in which the corrections have been included.
Please consider the following special shipment conditions for releases Enterprise R/3 4.7 and higher:
The objects to be corrected are part of software component SAP_HRXX. This software component contains country-independent objects of SAP_HR which, according to Note 1167891, are shipped twice a year in so-called Synchronization HRSPs. Given the priority of the issue, the corrections have been included in the next available HRSP for each release, although they are not Synchronization HRSPs.
These next available HRSPs are:
- Enterprise R/3 4.7 – SAPK-470A6INSAPHRRXX
- ECC 5.00 – SAPK-50072INSAPHRRXX
- ECC 6.00 – SAPK-60055INSAPHRRXX
- ECC 6.04 – SAPK-60421INSAPHRRXX
Customers that have chosen the CLC mode to implement HRSPs (Note 1167891) will only receive the corrections in the next Synchronization HRSPs and not as part of the CLC deliveries of the next available HRSPs, as the CLC delivery only contains country-specific objects.
Customers that have not chosen the CLC mode to implement HRSPs will receive the correction with the HRSPs mentioned above. No special testing is necessary as obsolete and unused ABAP code is deleted by this correction.
References
- Automatic checks for security notes using RSECNOTE (outdated)
- Announcement: New HCM Legal Change Delivery Process
Full note on SAP: SAP Support Launchpad note 1450128
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



