SAP Security Note
High priority
SAP security note 1594110, “Code Injection Vulnerability in Function & Class Builder”, released on March 13, 2012. Below are the symptom and the affected software components.
Description
Symptom
SAP has released Security Note 1594110 addressing a critical code injection vulnerability in the ABAP Function Builder and ABAP Class Builder. This vulnerability allows malicious users to execute arbitrary program code, potentially leading to system compromise or privilege escalation without legitimate credentials.
Reason and prerequisites
Ensure that the following SAP Notes are applied before implementing this security note: 506765, 972722, 1058934, 1118533.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
References
- Security Note 1638520 – Update #1 to Security Note 1594110
- SAP Note 1689538 – Development authorization S_DEVELOP for Customizing change
- SAP Note 1487329 – Additional Authorization Check in ABAP Workbench
Affected components
- SAP_BASIS: 46B to 802
- ABAP Workbench
- Java IDE and Infrastructure
- Workbench Tools: Editors, Painter, Modeler
- Function Builder (BC-DWB-TOO-FUB)
Full note on SAP: SAP Support Launchpad note 1594110
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
