Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Command injection vulnerability in MFG-MII, SAP security note 1614259

SAP Note 1614259

SAP security note 1614259, "Command injection vulnerability in MFG-MII". Below are the symptom and the SAP recommended solution.

Description

Symptom

MFG-MII contains code that permits the execution of operating system commands of the user’s choice. A malicious user can therefore control the behavior of the system.

Solution

All the malicious code has been removed in MII 12.1 SP06 and MII 12.2 SP02. Update to the above-mentioned releases to get the changes.

Reason and prerequisites

The program code contains a possibility to receive user input that allows the execution of operating system commands. This might change the behavior of the system. The user can:

  • Inject and run dangerous operating system commands
  • Obtain additional information that should not be displayed
  • Modify data, delete data
  • Modify the output of the system
  • Create new users with higher privileges
  • Perform a denial of service attack

Full note on SAP: SAP Support Launchpad note 1614259

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More