SAP Security Note
High priority
SAP security note 1831985, “Command Injection Vulnerability in SAP Netweaver IdM”, is a program error note released on June 11, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
The Identity Management User Interface contained code that permitted an attacker to inject code to control the behavior of the system.
An end user can assign themselves any business role or potentially any privilege without approval. A valid and authenticated user is required.
Solution
Apply the attached patches for the following versions:
- SAP NetWeaver Identity Management 7.1 SP7 User Interface
- SAP NetWeaver Identity Management 7.2 SP7 User Interface
No patch is required as of:
- SAP NetWeaver Identity Management 7.1 SP8
- SAP NetWeaver Identity Management 7.2 SP8
References
Full note on SAP: SAP Support Launchpad note 1831985
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




