Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Dll Hijacking in SAP Financial Consolidation, SAP security note 2172049

SAP Note 2172049
SAP Security Note
Medium priority

SAP security note 2172049, "Dll Hijacking in SAP Financial Consolidation", was released on 13.09.2016. Below are the symptom, SAP recommended solution and affected software components.

ComponentEnterprise Performance Management > Financial Consolidation (FC) > Technical Components
PriorityMedium priority
TypeSAP Security Note
StatusReleased for Customer
Released on13.09.2016

Description

Symptom

An unwanted DLL may be loaded by SAP Financial Consolidation.

SAP Financial Consolidation uses English as the default language and loads the English DLL resource to retrieve default localized strings. The corresponding DLL will be missing if English is not installed.

The product tries to load the missing DLL in all paths configured in the PATH environment variable. An attacker with access to one of the referenced paths could replace the existing DLL with a malicious DLL of the same name, which would then be loaded for victim users.

Solution

SAP Financial Consolidation has been updated to load the DLL only from the installation folder. The folders referenced in the PATH environment variable are now ignored.

CVSS

Score 4.5 Vector: AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected components

  • FINANCE 1000

Full note on SAP: SAP Support Launchpad note 2172049

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More