Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in SAP HANA XS, SAP security note 2098906

SAP Note 2098906

SAP security note 2098906, "Code injection vulnerability in SAP HANA XS", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

SAP HANA Extended Application Services (XS) contains code that permits the execution of program code that can lead to elevation of the user's privileges.

Solution

The issue is fixed with revision 85 for SAP HANA SPS08 and later revisions (including SPS09). Update to at least revision 85.

Reason and prerequisites

The program code contains a possibility to define and execute user-defined code that changes the behavior of the system. The vulnerability can only be exploited by a valid and authenticated user with developer privileges on the system.

CVSS

Score 7.1 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C

Full note on SAP: SAP Support Launchpad note 2098906

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More