SAP security note 2958563, "[CVE-2020-6318] Code Injection vulnerability in SAP NetWeaver (ABAP Server) and ABAP Platform". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).
Because of this, an attacker can exploit these products potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.
Solution
By applying the correction, the values of specific input parameters are ignored.
Important: The vulnerability scenario is not relevant to the SAP ABAP for Cloud Environment, and the described attack cannot be executed in SAP cloud products.
To resolve the issue, please apply the Support Package referenced by this SAP Note or use the correction instructions attached to this SAP Note.
Reason and prerequisites
The vulnerable code is present in some function modules, which belong to SAP Business Warehouse.
Note that the vulnerability is platform specific, meaning only ABAP Servers on DB4 or Sybase are vulnerable.
CVSS
Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
References
Affected components
- SAP Business Warehouse > Basis System and Installation > BW Database Platforms > BW on Adaptive Server Enterprise (BW-SYS-DB-SYB)
Full note on SAP: SAP Support Launchpad note 2958563
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
