HotNews
SAP security note 1668224, “Delete SOHMBEANS”, released on September 11, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can execute AA_EXECUTE_OS_COMMAND, which should be restricted as it enables OS command execution. This vulnerability may lead to privilege escalation.
Solution
The AA_EXECUTE_OS_COMMAND function is obsolete and has been deleted from the relevant codelines. This will not impact any existing functionality. Apply the Support Packages as described in SAP Note 1660315 to implement the fix.
CVSS
Score 7.5 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:C
References
Full note on SAP: SAP Support Launchpad note 1668224
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
