SAP security note 1656265, "Potential Execution of Dangerous OS Commands in BW-WHM". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BW-WHM contains a vulnerability that allows a malicious user to execute arbitrary programs on the system where BW-WHM is running. This can result in unauthorized system control, privilege escalation, tampering, data modification or deletion, and potential denial-of-service attacks. Exploiting this vulnerability requires a valid, authenticated user with the authorization object S_LOG_COM.
Solution
To mitigate this vulnerability, import the appropriate Support Package for your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: Support Package 29 (SAPKW70029)
- SAP NetWeaver BW 7.01: Support Package 11 (SAPKW70111)
- SAP NetWeaver BW 7.02: Support Package 11 (SAPKW70211)
- SAP NetWeaver BW 7.11: Support Package 09 (SAPKW71109)
- SAP NetWeaver BW 7.30: Support Package 7 (SAPKW73007)
- SAP NetWeaver BW 7.31 EHP 3: Support Package 3 (SAPKW73103)
References
Affected components
- SAP NetWeaver BW 7.00
- SAP NetWeaver BW 7.01
- SAP NetWeaver BW 7.02
- SAP NetWeaver BW 7.11
- SAP NetWeaver BW 7.30
- SAP NetWeaver BW 7.31
Full note on SAP: SAP Support Launchpad note 1656265
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




