Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in SAP HANA Web-based Development Workbench, SAP security note 2153892

SAP Note 2153892

SAP security note 2153892, "Code injection vulnerability in SAP HANA Web-based Development Workbench". Below are the symptom and SAP recommended solution.

Description

Symptom

SAP HANA Web-based Development Workbench contains code that permits attackers to use specially crafted inputs to modify database commands. This can result in either the retrieval of additional information or the modification of data persisted by the system.

Solution

The issue has been fixed with:

  • HANA revision 93 (for SPS09)
  • Revision 85.3 (for SPS08)

Ensure to update at least to these revisions.

Reason and prerequisites

Exploiting this vulnerability allows attackers to perform code injection, potentially leading to unauthorized data access or modification.

The attacker needs a valid user account with sap.hana.xs.ide.roles::Developer or sap.hana.xs.ide.roles::EditorDeveloper roles to perform the attack.

CVSS

Score 6.0 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

References

Full note on SAP: SAP Support Launchpad note 2153892

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More