SAP Security Note
HotNews
SAP security note 3119365, "Critical Code Injection Vulnerability (CVE-2021-44231)", is a program error note released on 14.12.2021. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker with low privileges can exploit a weakness in internally used text extraction reports (Translation Tools) to execute arbitrary commands in the background. This allows the attacker to control the behavior of the application, compromising all its data.
Solution
- Coding is deactivated (commented out).
- Please apply/implement this note.
- There is no impact on existing functionality.
Reason and prerequisites
Internally used reports were released by accident.
CVSS
Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected components
- SAP_BASIS: 701, 740, 750 to 756, 786, 804
Full note on SAP: SAP Support Launchpad note 3119365
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
