SAP security note 1906212, "Code Injection Vulnerability in Knowledge Provider". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This note has been updated. Please refer to note 2525392 for the current version.
Knowledge Provider contains a vulnerability through which an attacker can potentially execute a local command.
Solution
Implement the code correction via SNOTE. Alternatively, upgrade to the relevant Support Package.
Implement notes in the following order for a complete fix:
Reason and prerequisites
This vulnerability is due to a program error.
CVSS
Score 6.5 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Affected components
- SAP_BASIS 46C
- SAP_BASIS 701
- SAP_BASIS 711 to 730
- SAP_BASIS 731
- SAP_BASIS 740
Full note on SAP: SAP Support Launchpad note 1906212
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



