SAP Security Note
High priority
SAP security note 1489098, "Injecting ABAP code in transaction GENC", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Transaction GENC contains a branch to the ABAP Editor for reports generated in this transaction, which may enable a malicious user to inject and execute program code of the user’s choice.
Solution
By implementing the corrections, transaction GENC is no longer executed in the production environment.
Reason and prerequisites
The program contains instructions that enable a user to execute code of the user’s choice, which changes the system’s behavior. In this case, the user must be logged on to the system with a valid access.
Depending on the code that the user injects, the user may obtain additional information to which no actual access was granted. The user may also be able to modify data, delete data, modify the output of the system, or create new users with higher privileges. The availability of the system is still endangered.
CVSS
Score 0
Affected components
- SAP_APPL 31I
- SAP_APPL 40B
- SAP_APPL 45B
- SAP_APPL 46B
- SAP_APPL 46C
- SAP_APPL 470
- SAP_APPL 500
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
Full note on SAP: SAP Support Launchpad note 1489098
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



