SAP security note 2098906, "Code injection vulnerability in SAP HANA XS", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP HANA Extended Application Services (XS) contains code that permits the execution of program code that can lead to elevation of the user's privileges.
Solution
The issue is fixed with revision 85 for SAP HANA SPS08 and later revisions (including SPS09). Update to at least revision 85.
Reason and prerequisites
The program code contains a possibility to define and execute user-defined code that changes the behavior of the system. The vulnerability can only be exploited by a valid and authenticated user with developer privileges on the system.
CVSS
Score 7.1 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C
Full note on SAP: SAP Support Launchpad note 2098906
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




