SAP security note 2015446, “Unauthorized use of application functions in SAP HANA Web-based Development Workbench via code injection”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can execute functions in SAP HANA Web-based Development Workbench through code injection.
Solution
Update your SAP HANA installation to revision 74. SPS06 is not affected by this issue.
Reason and prerequisites
The attacker needs a valid user account with sap.hana.xs.ide.roles::Developer or sap.hana.xs.ide.roles::EditorDeveloper to perform the attack.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 2015446
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
