Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update 1 to Security Note 2808158 CVE-2019-0330 OS Command Injection vulnerability in SAP Diagnostics Agent, SAP security note 2823733

SAP Note 2823733
SAP Security Note
HotNews

SAP security note 2823733, "Update 1 to Security Note 2808158: [CVE-2019-0330] OS Command Injection vulnerability in SAP Diagnostics Agent", is a program error note released on 12.11.2019. Below are the symptom and SAP recommended solution.

ComponentService > SAP Solution Manager > Diagnostics > Infrastructure / Framework > Agent Framework
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on12.11.2019
LanguageEnglish

Description

Symptom

SAP Security Note 2823733 addresses a critical OS Command Injection vulnerability in the SAP Diagnostics Agent, identified as CVE-2019-0330. This update replaces the corrections provided in Security Note 2808158.

The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console allow an attacker to inject code that can be executed by the application. This vulnerability enables an attacker to control the behavior of the application through:

  • Unauthorized execution of commands
  • Sensitive information disclosure
  • Denial of Service

Solution

Apply the new LM_SERVICE patch as per the referenced SAP Notes for your Support Package. Ensure that the number of allowed control characters is reduced and verify that all used commands, especially those manually added to commands.xml, continue to function correctly.

CVSS

Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2823733

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More