Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential execution of dangerous OS commands in BW-WHM, SAP security note 1656265

SAP Note 1656265

SAP security note 1656265, "Potential Execution of Dangerous OS Commands in BW-WHM". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

BW-WHM contains a vulnerability that allows a malicious user to execute arbitrary programs on the system where BW-WHM is running. This can result in unauthorized system control, privilege escalation, tampering, data modification or deletion, and potential denial-of-service attacks. Exploiting this vulnerability requires a valid, authenticated user with the authorization object S_LOG_COM.

Solution

To mitigate this vulnerability, import the appropriate Support Package for your SAP NetWeaver BW version:

References

Affected components

  • SAP NetWeaver BW 7.00
  • SAP NetWeaver BW 7.01
  • SAP NetWeaver BW 7.02
  • SAP NetWeaver BW 7.11
  • SAP NetWeaver BW 7.30
  • SAP NetWeaver BW 7.31

Full note on SAP: SAP Support Launchpad note 1656265

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More