Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26828 Formula Injection in SAP Disclosure Management, SAP security note 2971180

SAP Note 2971180
SAP Security Note
Medium priority

SAP security note 2971180, “[CVE-2020-26828] Formula Injection in SAP Disclosure Management”, is released on 08.12.2020. Below are the symptom and the SAP recommended solution.

ComponentEnterprise Performance Management > SAP Disclosure Management (DM) > DM core functionalities
PriorityCorrection with medium priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on08.12.2020

Description

Symptom

SAP Disclosure Management allows authorized users to upload and download content of specific file types. In some file types, it is possible to enter formulas that can call external applications or execute scripts. This vulnerability allows an attacker to execute a payload (script) on the target machine, which could be used to steal and modify data in the spreadsheet.

Affected versions: SAP Disclosure Management 10.1 up to Stack 160x.

Solution

Upgrade SAP Disclosure Management to version 10.1 Stack 1700 or later. The file check introduced in 10.1 Stack 1200 has been enhanced to prevent uploads of files containing malicious formulas. Note that the solution might slightly impact upload times.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2971180

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.