Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in SCM-APO-PPS, SAP security note 1504090

SAP Note 1504090

SAP security note 1504090, "Code injection vulnerability in SCM-APO-PPS". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SCM-APO-PPS contains code that allows the execution of arbitrary program code chosen by the user. A malicious user can control the system’s behavior or potentially escalate privileges by executing malicious code without legitimate credentials.

Solution

The obsolete code line has been removed. Implement the necessary source code corrections to address the vulnerability.

Reason and prerequisites

The program code allows the definition and execution of user-supplied code, altering the system’s behavior. A valid and authenticated user is required. Depending on the injected code, a user can:

  • Inject and run their own code
  • Obtain additional sensitive information
  • Modify or delete data
  • Alter system output
  • Create new users with higher privileges
  • Perform denial of service attacks

CVSS

Score 0

References

Affected components

  • SAP_APO: Versions 30A to 310
  • SCM: Versions 400 to 701

Full note on SAP: SAP Support Launchpad note 1504090

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More