SAP security note 2153892, "Code injection vulnerability in SAP HANA Web-based Development Workbench". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP HANA Web-based Development Workbench contains code that permits attackers to use specially crafted inputs to modify database commands. This can result in either the retrieval of additional information or the modification of data persisted by the system.
Solution
The issue has been fixed with:
- HANA revision 93 (for SPS09)
- Revision 85.3 (for SPS08)
Ensure to update at least to these revisions.
Reason and prerequisites
Exploiting this vulnerability allows attackers to perform code injection, potentially leading to unauthorized data access or modification.
The attacker needs a valid user account with sap.hana.xs.ide.roles::Developer or sap.hana.xs.ide.roles::EditorDeveloper roles to perform the attack.
CVSS
Score 6.0 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P
References
Full note on SAP: SAP Support Launchpad note 2153892
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



