Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in SAP HANA Web-based Development Workbench via code injection, SAP security note 2015446

SAP Note 2015446

SAP security note 2015446, “Unauthorized use of application functions in SAP HANA Web-based Development Workbench via code injection”, is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can execute functions in SAP HANA Web-based Development Workbench through code injection.

Solution

Update your SAP HANA installation to revision 74. SPS06 is not affected by this issue.

Reason and prerequisites

The attacker needs a valid user account with sap.hana.xs.ide.roles::Developer or sap.hana.xs.ide.roles::EditorDeveloper to perform the attack.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

Full note on SAP: SAP Support Launchpad note 2015446

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More