SAP Security Note
Medium priority
SAP security note 2971180, “[CVE-2020-26828] Formula Injection in SAP Disclosure Management”, is released on 08.12.2020. Below are the symptom and the SAP recommended solution.
Description
Symptom
SAP Disclosure Management allows authorized users to upload and download content of specific file types. In some file types, it is possible to enter formulas that can call external applications or execute scripts. This vulnerability allows an attacker to execute a payload (script) on the target machine, which could be used to steal and modify data in the spreadsheet.
Affected versions: SAP Disclosure Management 10.1 up to Stack 160x.
Solution
Upgrade SAP Disclosure Management to version 10.1 Stack 1700 or later. The file check introduced in 10.1 Stack 1200 has been enhanced to prevent uploads of files containing malicious formulas. Note that the solution might slightly impact upload times.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2971180
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




