Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6262 Code Injection vulnerability in Service Data Download, SAP security note 2835979

SAP Note 2835979

SAP security note 2835979, "[CVE-2020-6262] Code Injection Vulnerability in Service Data Download". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Service Data Download (a part of the SAP Solution Manager Plugin) allows an attacker to inject code that can be executed by the application. This vulnerability enables an attacker to control the behavior of the application and the entire ABAP system.

  • Unauthorized execution of commands
  • Sensitive information disclosure
  • Denial of Service

Solution

Implement the SAP Security Note 2835979. The implementation of this note has no impact on any productive business processes.

This document is causing side effects with SAP Note 2930680: "Only on 4.6C: Correction for Side Effect of SAP Note 2835979 ‘Statement "RETURN" is not defined’".

Reason and prerequisites

Missing Input Validation for RFC function module.

CVSS

Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

References

  • SAP Note 1490437 – required for software components ST-PI from 2008_1_46C to 2008_1_710.

Affected components

  • ST-PI 2008_1_46C to 2008_1_46C
  • ST-PI 2008_1_620 to 2008_1_620
  • ST-PI 2008_1_640 to 2008_1_640
  • ST-PI 2008_1_700 to 2008_1_700+
  • ST-PI 2008_1_710 to 2008_1_710
  • ST-PI 740 to 740+

Full note on SAP: SAP Support Launchpad note 2835979

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More