SAP security note 2525392, "[CVE-2018-2363] Update 2 to 1906212: Code injection vulnerability in Knowledge Provider.". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Note 2525392 addresses a critical code injection vulnerability in the Knowledge Provider component (BC-SRV-KPR-DMS). This vulnerability allows malicious users to execute arbitrary code, potentially leading to system behavior manipulation or privilege escalation without valid credentials.
Solution
To mitigate this vulnerability, implement SAP Note 2525392. This involves:
- Prerequisites: ensure the following notes are applied in order before applying this note: 1906212 – Code injection vulnerability in Knowledge Provider, 2278931 – Update 1 to 1906212: Code injection vulnerability in Knowledge Provider
- Apply SAP Note 2525392 using SNOTE.
- Review SAP GUI Security Settings: SAP GUI for Windows should restrict file/directory level access using GUI security settings; SAP GUI for Java: refer to the SAP GUI for Java documentation via Help → SAP GUI Help.
Note: Only absolute and valid URLs with protocols HTTP, HTTPS, and FILE are supported. Relative URLs are not supported.
CVSS
Score 6.5 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
References
- CVE-2018-2363
- 2278931 – Update 1 to 1906212: Code injection vulnerability in Knowledge Provider
- 1906212 – Code injection vulnerability in Knowledge Provider
Affected components
- SAP_BASIS versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752
Full note on SAP: SAP Support Launchpad note 2525392
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
