Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in FERCC001, SAP security note 1493101

SAP Note 1493101HotNews

SAP security note 1493101, "Code injection vulnerability in FERCC001", is released on December 14, 2010. Below are the symptom and SAP recommended solution.

ComponentFI-RRU (Regulatory Reporting for Utility Companies)
PriorityHotNews
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

FERCC001 permits the injection of user-defined code, which can alter system behavior. Although the program does not execute the injected code, it allows its creation, potentially leading to unauthorized modifications, data manipulation, or denial of service attacks.

Impact:

  • Injection of malicious code
  • Unauthorized access to sensitive information
  • Data modification or deletion
  • Creation of users with elevated privileges
  • Potential for denial of service attacks

Solution

Immediate action: apply the attached advanced correction as a temporary measure to mitigate the vulnerability.

Permanent fix: the vulnerable code will be removed through the relevant support packages.

Reason and prerequisites

The vulnerability arises from the program’s ability to define and inject user-supplied code, which can modify the system’s behavior if executed.

References

Full note on SAP: SAP Support Launchpad note 1493101

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More