Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0330 OS Command Injection vulnerability in SAP Diagnostics Agent, SAP security note 2808158

SAP Note 2808158
SAP Security Note
HotNews

SAP security note 2808158, "[CVE-2019-0330] OS Command Injection vulnerability in SAP Diagnostics Agent", is a program error note released on 12.11.2019. Below are the symptom and SAP recommended solution.

ComponentSV-SMG-DIA-SRV-AGT
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on12.11.2019
LanguageEnglish

Description

Symptom

UPDATE 12th November 2019: The SAP security note 2839864 replaces the corrections provided in this security note.

UPDATE 10th September 2019: The SAP security note 2823733 replaces the corrections provided in this security note.

The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

Impacts of Code Injection Vulnerability:

  • Unauthorized execution of commands
  • Sensitive information disclosure
  • Denial of Service

Solution

Customers should implement the corrections provided in SAP Note 2823733 for a complete fix.

CVSS

Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2808158

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More