SAP security note 1503375, "ED: Code injection vulnerability in functionality ‘Other’". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Functionality ‘Other’ contains code that allows the execution of arbitrary program code, enabling malicious users to control system behavior or escalate privileges without legitimate credentials.
A code injection vulnerability exists in the ‘Other’ functionality, allowing authenticated users to execute arbitrary code. This can lead to unauthorized actions such as modifying or deleting data, altering system output, creating users with higher privileges, or performing denial of service attacks.
Solution
Deactivate the obsolete coding and implement the correction provided via SNOTE. No further testing is required.
References
Affected components
- Industry-Specific Component Beverage > Excise Duties (IS-BEV-ED)
- IS-BEV: Versions 461 to 4602
- EA-APPL: Versions 200, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1503375
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
