SAP security note 2301837, "Code Injection vulnerability in SAP Solution Manager", is a program error note released on 26.07.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
A component of SAP Solution Manager allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Some well-known impacts of Code Injection vulnerability are:
- Unauthorized execution of commands
- Sensitive information disclosure
- Denial of Service
Solution
Affected obsolete code lines are now deleted. Implement the correction instructions provided in the note.
Reason and prerequisites
Method PING_HOST can be abused to execute unintended OS commands.
CVSS
Score 9.9 / 10 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Full note on SAP: SAP Support Launchpad note 2301837
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
