Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in System Administration Assistant, SAP security note 2248735

SAP Note 2248735

SAP security note 2248735, “Code injection vulnerability in System Administration Assistant”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The System Administration Assistant contains code that permits the execution of arbitrary operating system commands chosen by the user. This vulnerability allows an attacker to control the system's behavior or potentially escalate privileges by executing malicious code without needing legitimate user credentials.

Solution

The vulnerable code has been disabled. To mitigate this vulnerability, implement the correction instructions provided in this SAP Note.

Reason and prerequisites

A valid and authenticated user is required to exploit this vulnerability. Depending on the executed command, an attacker may gain access to and modify the server's operating system or network.

CVSS

Score 6.0 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Affected components

  • SAP_BASIS 700 to 702
  • SAP_BASIS 710 to 711
  • SAP_BASIS 730 to 731
  • SAP_BASIS 740 to 750

Full note on SAP: SAP Support Launchpad note 2248735

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More