SAP security note 2153898, "Multiple vulnerabilities have been discovered in HANA Web-based Development Workbench", is a note released on 21.05.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
SQL Injection (CVSS Score 4.9 / 10): allows attackers to modify database commands using specially crafted inputs, leading to data modification. Impact: modification of data persisted by the system.
Reflected Cross Site Scripting (XSS) (CVSS Score 4.3 / 10): enables attackers to modify application content and potentially steal authentication information. Impact: non-permanent defacement or modification of web content; possible theft of user authentication data.
Solution
Update to at least HANA revision 93 (for SPS09) or revision 85.2 (for SPS08).
Reason and prerequisites
An attacker requires a valid user account with the sap.hana.xs.ide.roles::* roles. The impact is limited to the SQL privileges granted to the user.
Full note on SAP: SAP Support Launchpad note 2153898
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
