Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

OS Command Injection vulnerability in Report for Terminology Export, SAP security note 2357141

SAP Note 2357141
SAP Security Note
HotNews

SAP security note 2357141, "OS Command Injection vulnerability in Report for Terminology Export", is a program error note released on 17.05.2018. Below are the symptom, CVSS score, SAP recommended solution and references.

ComponentBasis Components > Documentation and Translation Tools > Terminology/Glossary
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version10
StatusReleased for Customer
Released on17.05.2018
LanguageEnglish

Description

Symptom

UPDATE 17th May 2018: This note has been re-released with updated "Solution", "Attachments", "Validity of support package for SAP_BASIS 750 release extended to SP00 under Correction Instructions" and "References" information.

If this note has been already implemented, then there is no action required.

UPDATE 30th November: This note has been re-released with updated "Solution and Attachment" information.

Report for terminology export is vulnerable to OS command injection, allowing an authorized user with sufficient permissions to execute arbitrary OS commands. Customers using the terminology export report program are potentially affected.

Solution

As a fix, affected program code lines are deleted as the code lines were obsolete.

Implement the correction instructions referenced by this SAP Note.

CVSS

Score 9.1 / 10 Vector: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2357141

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More