SAP security note 1717391, "Code injection vulnerability in BC-BMT-WFM-DEF", addresses the following vulnerability. Below are the symptom, reason, SAP recommended solution, references and the affected software components.
Description
Symptom
BC-BMT-WFM-DEF contains code that permits the execution of arbitrary program code of the user’s choice. An attacker can control the system’s behavior or potentially escalate privileges by executing malicious code without possessing legitimate credentials.
Solution
Please apply the attached correction.
Reason and prerequisites
The program code allows defining and executing user-defined code that alters the system’s behavior.
References
Affected components
- SAP_BASIS: 620 to 731
Full note on SAP: SAP Support Launchpad note 1717391
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




