SAP security note 2835979, "[CVE-2020-6262] Code Injection Vulnerability in Service Data Download". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Service Data Download (a part of the SAP Solution Manager Plugin) allows an attacker to inject code that can be executed by the application. This vulnerability enables an attacker to control the behavior of the application and the entire ABAP system.
- Unauthorized execution of commands
- Sensitive information disclosure
- Denial of Service
Solution
Implement the SAP Security Note 2835979. The implementation of this note has no impact on any productive business processes.
This document is causing side effects with SAP Note 2930680: "Only on 4.6C: Correction for Side Effect of SAP Note 2835979 ‘Statement "RETURN" is not defined’".
Reason and prerequisites
Missing Input Validation for RFC function module.
CVSS
Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References
- SAP Note 1490437 – required for software components ST-PI from 2008_1_46C to 2008_1_710.
Affected components
- ST-PI 2008_1_46C to 2008_1_46C
- ST-PI 2008_1_620 to 2008_1_620
- ST-PI 2008_1_640 to 2008_1_640
- ST-PI 2008_1_700 to 2008_1_700+
- ST-PI 2008_1_710 to 2008_1_710
- ST-PI 740 to 740+
Full note on SAP: SAP Support Launchpad note 2835979
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
