Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Executing any source code using template report, SAP security note 1499627

SAP Note 1499627
SAP Security Note
High priority

SAP security note 1499627, “Executing any source code using template report”, is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.

ComponentControlling > Overhead Cost Controlling > Activity-Based Costing (CO-OM-ABC)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

By making specific entries in a table, an attacker can generate programs with harmful source code. The tables belong to the component CO-OM-ABC-F.

Solution

Navigate to the table maintenance for the tables COTPLFS and COTPL, and change the setting on the Delivery and Maintenance tab page from Display/Maintenance Allowed to Display/Maintenance Allowed with Restrictions, or import the relevant Support Package.

Then call transactions SE16 and SE16N for the tables COTPL and COTPLFS. It should no longer be possible to add or change entries.

Reason and prerequisites

The program code allows source code that can be freely determined to be added and executed, enabling an attacker to control the system response. Valid logon information is required for this.

The relevant program code must be stored in a database table. Therefore, an attacker requires authorization for transaction SE16 or SE16N as well as change authorization for the authorization object S_TABU_DIS.

With these authorizations, it is possible to make new entries in the tables because you have selected the "Display/Maintenance Allowed" option in the "Delivery and Maintenance" settings.

Full note on SAP: SAP Support Launchpad note 1499627

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More