Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SQL Injection vulnerability in SAP HANA Web Workbench, SAP security note 2428811

SAP Note 2428811
SAP Security Note
Low priority

SAP security note 2428811, "SQL Injection Vulnerability in SAP HANA Web Workbench", is a program error note released on March 14, 2017. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityCorrection with low priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onMarch 14, 2017
LanguageEnglish

Description

Symptom

The SAP HANA Web Workbench allows an authenticated user to execute crafted database queries. These queries can manipulate settings in the performance_analyzer section of the global.ini file. The SQL commands execute with the privileges of the calling user, and privilege escalation is not possible.

Solution

The issue has been fixed in the following revisions:

  • SAP HANA 1.00 SPS 12: Revision 122.06
  • SAP HANA 2.0 SPS 00: Revision 001

Update to these or later versions to resolve the vulnerability.

Reason and prerequisites

User must have been granted the following privileges:

  • TRACE ADMIN
  • INIFILE ADMIN

CVSS

Score 2.7/10 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2428811

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More