Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in SV-SMG-SDD, SAP security note 1641766

SAP Note 1641766

SAP security note 1641766, "Code injection vulnerability in SV-SMG-SDD". Below are the symptom and SAP recommended solution.

Description

Symptom

The component SV-SMG-SDD contains code that permits the execution of operating system commands of the user’s choice with a maximum length of 6 characters.

Solution

Implement the correction instructions of this note.

Reason and prerequisites

The program code contains a possibility to execute operating system commands of the user’s choice with a maximum length of 6 characters. A valid and authenticated user with authorization to execute transaction SE37 is required. Depending on the code, the user can:

  • Inject and run their own code
  • Obtain additional information that should not be displayed
  • Modify data, delete data
  • Modify the output of the system

Full note on SAP: SAP Support Launchpad note 1641766

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More