SAP Security Note
HotNews
SAP security note 2808158, "[CVE-2019-0330] OS Command Injection vulnerability in SAP Diagnostics Agent", is a program error note released on 12.11.2019. Below are the symptom and SAP recommended solution.
Description
Symptom
UPDATE 12th November 2019: The SAP security note 2839864 replaces the corrections provided in this security note.
UPDATE 10th September 2019: The SAP security note 2823733 replaces the corrections provided in this security note.
The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Impacts of Code Injection Vulnerability:
- Unauthorized execution of commands
- Sensitive information disclosure
- Denial of Service
Solution
Customers should implement the corrections provided in SAP Note 2823733 for a complete fix.
CVSS
Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
References
This note refers to
Full note on SAP: SAP Support Launchpad note 2808158
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



