Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Command Injection through Web Intelligence Report or DataProvider export, SAP security note 2561202

SAP Note 2561202

SAP security note 2561202, "Command Injection through Web Intelligence Report or DataProvider export", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

Users can insert unsafe Excel commands via Web Intelligence Data or Formula into a Report that will be executed by Excel when importing the exported CSV data from a Web Intelligence Report.

Solution

This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.

For the Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559.

Reason and prerequisites

This fix is required because Web Intelligence outputs are supposed to be trusted. The CSV output is now escaped to disable the Excel capability of transforming string data into commands when Excel reads some special characters.

Before the attacks can be performed, Excel users must manually accept running these commands.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2561202

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More