SAP security note 1550224, "Execute potentially dangerous commands in Visual Admin", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Visual Administrator tool contains a vulnerability through which a malicious user can potentially execute arbitrary programs on the server where the tool runs.
Solution
Upgrade your SAP J2EE Engine to a fixed version.
Reason and prerequisites
An option in the tool reveals the opportunity for a malicious user to be able to execute arbitrary programs on the server where the tool runs.
CVSS
Score 0
References
Affected components
- SAP-JEE: From 6.40 to 6.40
- SAP-JEE: From 7.00 to 7.02
- SAP-JEECOR: From 7.00 to 7.02
- CORE-TOOLS: From 7.00 to 7.02
Full note on SAP: SAP Support Launchpad note 1550224
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
