Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code Injection vulnerability in Governance, Risk and Compliance Access Controls, SAP security note 2453640

SAP Note 2453640Code Injection

SAP security note 2453640, "Code Injection Vulnerability in Governance, Risk and Compliance Access Controls". Below are the symptom and SAP recommended solution.

ComponentGovernance, Risk and Compliance > SAP Access Control > Access Request (GRC-SAC-ARQ)
TypeCode Injection

Description

Symptom

End users can input special characters, including potential OS commands, in template names. This vulnerability allows attackers to execute arbitrary code when exported spreadsheets are opened, manipulating the behavior of the application.

Solution

To mitigate this vulnerability, implement this SAP security note or upgrade to the latest support packages as specified below.

  • AC 10.0 – Support Package 26
  • AC 10.1 – Support Package 18
  • AC 8000 – Support Package 4

The SAP note restricts the use of special characters such as ~@#$%^&*()\?/<>|!+,.{}[] in template names, preventing code injection.

CVSS

Score 6.5

Full note on SAP: SAP Support Launchpad note 2453640

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More