SAP security note 1492434, "Executing arbitrary code using report RIWP_VIEW_GENERATE", is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
RIWP_VIEW_GENERATE contains code which allows a malicious user to execute arbitrary program code of the user’s choice. In this way, a malicious user can obtain control over the system and can obtain escalated privileges.
Solution
The report RIWP_VIEW_GENERATE is commented completely.
Reason and prerequisites
The program code contains a possibility to define and execute code of the user’s choice which changes the system’s behavior. Valid log on information is required for this purpose.
Depending on the inserted code, the malicious user can obtain unauthorized access to data and change or delete this data, but also change system outputs or create new users and cause a Denial of Service.
Full note on SAP: SAP Support Launchpad note 1492434
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
