SAP security note 2453640, "Code Injection Vulnerability in Governance, Risk and Compliance Access Controls". Below are the symptom and SAP recommended solution.
Description
Symptom
End users can input special characters, including potential OS commands, in template names. This vulnerability allows attackers to execute arbitrary code when exported spreadsheets are opened, manipulating the behavior of the application.
Solution
To mitigate this vulnerability, implement this SAP security note or upgrade to the latest support packages as specified below.
- AC 10.0 – Support Package 26
- AC 10.1 – Support Package 18
- AC 8000 – Support Package 4
The SAP note restricts the use of special characters such as ~@#$%^&*()\?/<>|!+,.{}[] in template names, preventing code injection.
CVSS
Score 6.5
Full note on SAP: SAP Support Launchpad note 2453640
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




