SAP Security Note
HotNews
SAP security note 2357141, "OS Command Injection vulnerability in Report for Terminology Export", is a program error note released on 17.05.2018. Below are the symptom, CVSS score, SAP recommended solution and references.
Description
Symptom
UPDATE 17th May 2018: This note has been re-released with updated "Solution", "Attachments", "Validity of support package for SAP_BASIS 750 release extended to SP00 under Correction Instructions" and "References" information.
If this note has been already implemented, then there is no action required.
UPDATE 30th November: This note has been re-released with updated "Solution and Attachment" information.
Report for terminology export is vulnerable to OS command injection, allowing an authorized user with sufficient permissions to execute arbitrary OS commands. Customers using the terminology export report program are potentially affected.
Solution
As a fix, affected program code lines are deleted as the code lines were obsolete.
Implement the correction instructions referenced by this SAP Note.
CVSS
Score 9.1 / 10 Vector: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
References
Full note on SAP: SAP Support Launchpad note 2357141
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




