Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2363 Update 2 to 1906212 Code injection vulnerability in Knowledge Provider., SAP security note 2525392

SAP Note 2525392

SAP security note 2525392, "[CVE-2018-2363] Update 2 to 1906212: Code injection vulnerability in Knowledge Provider.". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Note 2525392 addresses a critical code injection vulnerability in the Knowledge Provider component (BC-SRV-KPR-DMS). This vulnerability allows malicious users to execute arbitrary code, potentially leading to system behavior manipulation or privilege escalation without valid credentials.

Solution

To mitigate this vulnerability, implement SAP Note 2525392. This involves:

Note: Only absolute and valid URLs with protocols HTTP, HTTPS, and FILE are supported. Relative URLs are not supported.

CVSS

Score 6.5 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

References

Affected components

  • SAP_BASIS versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752

Full note on SAP: SAP Support Launchpad note 2525392

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More