Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code Injection vulnerability in Visual Composer 04s iviews, SAP security note 2376081

SAP Note 2376081

SAP security note 2376081, "Code Injection Vulnerability in Visual Composer 04s Iviews", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

UPDATE 10th April 2018: This note has been re-released with updated "Solution" information.

Visual Composer 04s iviews allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

Some well-known impacts of Code Injection vulnerability are:

  • Unauthorized execution of commands
  • Sensitive information disclosure
  • Denial of Service

Solution

In the export to Excel mechanism, the entire input stream received from Visual Composer is now being checked for Code Injection vulnerabilities.

After implementing this note, please implement SAP Note 2552318 for a complete solution.

Reason and prerequisites

Prerequisite: You are running Visual Composer iviews created in 04s versions.

Side effects

CVSS

Score 7.4 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

References

Affected components

  • VCFRAMEWORK (7.00 to 7.02)
  • VC70RUNTIME (7.30 to 7.50)

Full note on SAP: SAP Support Launchpad note 2376081

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More