Description
Symptom
An attacker with low privileges can exploit the weakness in internally used text extraction reports (Translation Tools) which will enable the execution of arbitrary commands in the background. An attacker could thereby control the behavior of the application compromising all its data.
Other Terms
Code Injection, Command Injection, OS command injection, CVE-2021-44231
Reason and Prerequisites
Internally used reports were released by accident.
Solution
- Coding is deactivated (commented out).
- Please apply/implement this note.
- There is no impact on existing functionality.
Available fix and Supported packages
SAP_BASIS |701|701
SAP_BASIS|804|804
SAP_BASIS|740|740
SAP_BASIS|750|756
SAP_BASIS|786|786
Affected component
SAP_BASIS
CVSS
Score: 9.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploit
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/3119365