Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in package S_CM_EXTRACT, SAP security note 1482180

SAP Note 1482180SAP Security NoteHigh priority

SAP security note 1482180, "Code Injection Vulnerability in Package S_CM_EXTRACT", released on December 14, 2010. Below are the symptom and SAP recommended solution.

ComponentCA-BFA-TRA (Cross-Application Components > Business Framework Architecture > Transceiver)
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

The vulnerability exists in the S_CM_EXTRACT package, where the code allows the execution of arbitrary program code defined by the user. This can lead to unauthorized control over the system, data manipulation, deletion, or the creation of users with elevated privileges.

  • Inject and execute their own code.
  • Access sensitive information.
  • Modify or delete data.
  • Alter system outputs.
  • Perform denial of service attacks.

Solution

The affected code belongs to an obsolete program that is no longer in use. Implementing this security note will comment out the vulnerable code, mitigating the risk.

Implementing this note may affect SAP Note 1696811, which deals with an error in report SAPRCKAPP02_WP "Display of Data Extracts".

Full note on SAP: SAP Support Launchpad note 1482180

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More