SAP Security Note
Medium priority
SAP security note 1466530, "Code Injection Vulnerability in a BW Function Module", was released on 20.10.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
A function module in BW contains code that allows the execution of arbitrary program code chosen by the user. This vulnerability enables a malicious user to control system behavior or potentially escalate privileges by executing malicious code without possessing legitimate credentials.
Solution
Apply the relevant SAP Note or Support Package. Note: This note requires an update to the SNOTE tool via Note 875986.
Reason and prerequisites
The program code allows users to define and execute their own code, altering the system’s behavior. While a valid and authenticated user is required, the vulnerability can be exploited to:
- Inject and run unauthorized code
- Access sensitive information
- Modify or delete data
- Alter system outputs
- Create new users with higher privileges
- Perform denial of service attacks
Full note on SAP: SAP Support Launchpad note 1466530
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



