Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Command injection vulnerability in SAP Netweaver IdM, SAP security note 1831985

SAP Note 1831985
SAP Security Note
High priority

SAP security note 1831985, “Command Injection Vulnerability in SAP Netweaver IdM”, is a program error note released on June 11, 2013. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Identity and Access Management > Identity Management (BC-IAM-IDM)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onJune 11, 2013
LanguageEnglish

Description

Symptom

The Identity Management User Interface contained code that permitted an attacker to inject code to control the behavior of the system.

An end user can assign themselves any business role or potentially any privilege without approval. A valid and authenticated user is required.

Solution

Apply the attached patches for the following versions:

  • SAP NetWeaver Identity Management 7.1 SP7 User Interface
  • SAP NetWeaver Identity Management 7.2 SP7 User Interface

No patch is required as of:

  • SAP NetWeaver Identity Management 7.1 SP8
  • SAP NetWeaver Identity Management 7.2 SP8

References

Full note on SAP: SAP Support Launchpad note 1831985

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More