SAP security note 1614259, "Command injection vulnerability in MFG-MII". Below are the symptom and the SAP recommended solution.
Description
Symptom
MFG-MII contains code that permits the execution of operating system commands of the user’s choice. A malicious user can therefore control the behavior of the system.
Solution
All the malicious code has been removed in MII 12.1 SP06 and MII 12.2 SP02. Update to the above-mentioned releases to get the changes.
Reason and prerequisites
The program code contains a possibility to receive user input that allows the execution of operating system commands. This might change the behavior of the system. The user can:
- Inject and run dangerous operating system commands
- Obtain additional information that should not be displayed
- Modify data, delete data
- Modify the output of the system
- Create new users with higher privileges
- Perform a denial of service attack
Full note on SAP: SAP Support Launchpad note 1614259
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
