HotNews
SAP security note 2999854, "[CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA", released on April 27, 2021. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Business Warehouse and SAP BW/4HANA are vulnerable to a code injection flaw that allows a low-privileged attacker to inject malicious ABAP code using a remote-enabled function module over the network. Due to insufficient input validation, an attacker with S_RFC access can execute this function module to insert malicious code, which is then saved persistently in a report within the ABAP repository. Executing this report can lead to:
- Sensitive data loss
- Modification of critical data
- Denial of service
Solution
To mitigate this vulnerability, implement the correction instructions provided in the SAP Note. The solution involves adding additional validation for all input data in the affected function to prevent malicious inputs from reaching the database.
CVSS
Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References
- SAP Note 1884876: Debug report generated with syntax error
- SAP Note 2099301: Error analysis – catching queries that fail on the BWA
- Q&A for SAP Security Note 2999854
Affected components
- DW4CORE: 100, 200
- SAP_BW: 700 to 702, 711, 730 to 731, 740, 750 to 755, 782
Full note on SAP: SAP Support Launchpad note 2999854
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
