Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code Injection vulnerability in SAP Solution Manager, SAP security note 2301837

SAP Note 2301837SAP Security NoteHotNews

SAP security note 2301837, "Code Injection vulnerability in SAP Solution Manager", is a program error note released on 26.07.2016. Below are the symptom and SAP recommended solution.

ComponentSV-SMG-INS-CFG
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version9
StatusReleased for Customer
Released on26.07.2016
LanguageEnglish

Description

Symptom

A component of SAP Solution Manager allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

Some well-known impacts of Code Injection vulnerability are:

  • Unauthorized execution of commands
  • Sensitive information disclosure
  • Denial of Service

Solution

Affected obsolete code lines are now deleted. Implement the correction instructions provided in the note.

Reason and prerequisites

Method PING_HOST can be abused to execute unintended OS commands.

CVSS

Score 9.9 / 10 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Full note on SAP: SAP Support Launchpad note 2301837

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More