Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

BRF+ Syntax error and code injection vulnerability, SAP security note 1584602

Description

This note was previously released as a functional note. If this note has already been applied to your system no further actions are required.

For Action Email and Message Log, if the character “`” is used in the email body or message text respectively, then generation fails with a syntax error. Also, the mishandling of the character “`” permits a malicious user the execution of arbitrary code. A malicious user can therefore control the behavior of the system, or can potentially escalate privileges by executing malicious code.

Available fix and Supported packages

  • SAP_BASIS | 701 | 702
  • SAP_BASIS | 730 | 730
  • SAP_BASIS 701 | SAPKB70110 |
  • SAP_BASIS 702 | SAPKB70209 |
  • SAP_BASIS 730 | SAPKB73004 |

Affected component

    BC-SRV-BR
    BRFplus – ABAP based Rule Framework

CVSS

Score: 0

Exploit

Exploit is not available.
For detailed information please contact the mail [email protected]

URL

https://launchpad.support.sap.com/#/notes/1584602

TAGS

#BRF+
#BRFplus
#Injection
#CL_FDT_ACTN_MESSAGE_LOG
#CL_FDT_ACTN_EMAIL
#PROCESS_PURE
#LITERALS
#BC-SRV-BR

More to explorer