High priority
SAP security note 1641329, "Code injection vulnerability in SV-SMG-SDD", is a program error note released on February 14, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
The component SV-SMG-SDD contains code that allows the execution of operating system commands of the user’s choice with a maximum length of 6 characters. This vulnerability affects the Service Data Control Center (transaction SDCCN), specifically the "Export Session Data to File" task.
A valid and authenticated user with authorization to execute transaction SE37 can exploit this vulnerability to:
- Inject and run their own code.
- Obtain additional information that should not be displayed.
- Modify or delete data.
- Alter the system’s output.
Solution
For SAP_BASIS releases 610 – 731: Implement the correction instructions provided in this note.
For SAP_BASIS releases 46B – 46D: If ST-PI Add-on is Installed, the issue does not occur and no further action is required. If ST-PI Add-on is Not Installed, install the ST-PI add-on on your system. Refer to Note 769623 (ST-PI 2005_1_46B and ST-PI 2005_1_46D) or Note 1228898 (ST-PI 2008_1_46C) for detailed installation instructions.
CVSS
Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1641329
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
