Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in program VRS_TABLE_COMPARISON, SAP security note 1502386

SAP Note 1502386
Medium priority

SAP security note 1502386, “Code injection vulnerability in program VRS_TABLE_COMPARISON”, was released on November 12, 2010. Below are the symptom and the SAP recommended solution.

ComponentBasis Components > Change and Transport System > Workbench/Customizing Organizer
PriorityCorrection with medium priority
StatusReleased for Customer
Released onNovember 12, 2010

Description

Symptom

Program VRS_TABLE_COMPARISON contains code that allows the execution of arbitrary program code of the user’s choice. A malicious user can control the system’s behavior. This Security Note has been updated. See Security Note 1520840 for details.

Solution

Install the appropriate support package to disable program VRS_TABLE_COMPARISON. The required support packages are listed below based on your SAP_BASIS version:

Reason and prerequisites

The program code allows users to execute arbitrary code, altering the system’s behavior. Depending on the injected code, a user may:

  • Obtain additional information not intended to be displayed
  • Modify or delete data
  • Alter system output
  • Create new users with higher privileges
  • Perform a denial of service attack

Note: VRS_TABLE_COMPARISON is an internal program not part of any standard transaction or typically executed in standard SAP systems. Exploiting this vulnerability requires unrestricted system access, meaning it cannot be used to gain additional access rights but can obscure an attack by adding intermediate steps that complicate analysis.

Full note on SAP: SAP Support Launchpad note 1502386

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More