SAP Security Note
High priority
SAP security note 2085588, “Code Injection Vulnerability in SV-SMG-SDD”, is a program error note released on 21.05.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
SV-SMG-SDD contains code that permits the execution of arbitrary OS commands on the SAP application server. An attacker can control the system’s behavior or potentially escalate privileges by executing malicious code without having legitimate credentials.
Solution
Implement the correction instructions provided in SAP Security Note 2085588.
CVSS
Score 6.0 / 10 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 2085588
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
