Medium priority
SAP security note 1502386, “Code injection vulnerability in program VRS_TABLE_COMPARISON”, was released on November 12, 2010. Below are the symptom and the SAP recommended solution.
Description
Symptom
Program VRS_TABLE_COMPARISON contains code that allows the execution of arbitrary program code of the user’s choice. A malicious user can control the system’s behavior. This Security Note has been updated. See Security Note 1520840 for details.
Solution
Install the appropriate support package to disable program VRS_TABLE_COMPARISON. The required support packages are listed below based on your SAP_BASIS version:
- SAP_BASIS 6.40: SAPKB64027
- SAP_BASIS 7.00: SAPKB70023
- SAP_BASIS 7.01: SAPKB70108
- SAP_BASIS 7.02: SAPKB70206
- SAP_BASIS 7.10: SAPKB71011
- SAP_BASIS 7.11: SAPKB71106
- SAP_BASIS 7.20: SAPKB72004
- SAP_BASIS 7.30: SAPKB73001
Reason and prerequisites
The program code allows users to execute arbitrary code, altering the system’s behavior. Depending on the injected code, a user may:
- Obtain additional information not intended to be displayed
- Modify or delete data
- Alter system output
- Create new users with higher privileges
- Perform a denial of service attack
Note: VRS_TABLE_COMPARISON is an internal program not part of any standard transaction or typically executed in standard SAP systems. Exploiting this vulnerability requires unrestricted system access, meaning it cannot be used to gain additional access rights but can obscure an attack by adding intermediate steps that complicate analysis.
Full note on SAP: SAP Support Launchpad note 1502386
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
