SAP security note 2774489, "[CVE-2019-0328] Code Injection vulnerability in ABAP Tests Modules of SAP NetWeaver Process Integration". Below are the symptom and the SAP recommended solution.
Description
Symptom
ABAP Tests Modules of SAP NetWeaver Process Integration enables an attacker to execute OS commands with privileged rights. An attacker could thereby impact the integrity and availability of the system.
Solution
Implement the attached Correction Instructions or import the specified Support Package.
The source code of the affected modules has been adjusted to prevent OS command execution. After implementing the correction, the vulnerability is closed and no longer exploitable.
CVSS
Score 8.7 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Full note on SAP: SAP Support Launchpad note 2774489
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
