Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in SV-SMG-SDD, SAP security note 1641329

SAP Note 1641329
High priority

SAP security note 1641329, "Code injection vulnerability in SV-SMG-SDD", is a program error note released on February 14, 2012. Below are the symptom and SAP recommended solution.

CategoryProgram Error
PriorityCorrection with High Priority
StatusReleased for Customer
Released onFebruary 14, 2012

Description

Symptom

The component SV-SMG-SDD contains code that allows the execution of operating system commands of the user’s choice with a maximum length of 6 characters. This vulnerability affects the Service Data Control Center (transaction SDCCN), specifically the "Export Session Data to File" task.

A valid and authenticated user with authorization to execute transaction SE37 can exploit this vulnerability to:

  • Inject and run their own code.
  • Obtain additional information that should not be displayed.
  • Modify or delete data.
  • Alter the system’s output.

Solution

For SAP_BASIS releases 610 – 731: Implement the correction instructions provided in this note.

For SAP_BASIS releases 46B – 46D: If ST-PI Add-on is Installed, the issue does not occur and no further action is required. If ST-PI Add-on is Not Installed, install the ST-PI add-on on your system. Refer to Note 769623 (ST-PI 2005_1_46B and ST-PI 2005_1_46D) or Note 1228898 (ST-PI 2008_1_46C) for detailed installation instructions.

CVSS

Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P

Full note on SAP: SAP Support Launchpad note 1641329

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More