SAP security note 2376081, "Code Injection Vulnerability in Visual Composer 04s Iviews", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 10th April 2018: This note has been re-released with updated "Solution" information.
Visual Composer 04s iviews allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Some well-known impacts of Code Injection vulnerability are:
- Unauthorized execution of commands
- Sensitive information disclosure
- Denial of Service
Solution
In the export to Excel mechanism, the entire input stream received from Visual Composer is now being checked for Code Injection vulnerabilities.
After implementing this note, please implement SAP Note 2552318 for a complete solution.
Reason and prerequisites
Prerequisite: You are running Visual Composer iviews created in 04s versions.
Side effects
CVSS
Score 7.4 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
References
This note refers to
Referenced by
- SAP Note 2566973 – Collective Note: SAP NetWeaver 7.30 SP18 – Enterprise Portal
- SAP Note 2332246 – Collective Note: SAP NetWeaver 7.30 SP17 – Enterprise Portal
- SAP Note 2555602 – Central Note: SAP NetWeaver 7.5 SP10 – Enterprise Portal
- SAP Note 2484466 – Central Note: SAP NetWeaver 7.5 SP09 – Enterprise Portal
- SAP Note 2441153 – Central Note: SAP NetWeaver 7.5 SP08 – Enterprise Portal
Affected components
- VCFRAMEWORK (7.00 to 7.02)
- VC70RUNTIME (7.30 to 7.50)
Full note on SAP: SAP Support Launchpad note 2376081
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
