Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Multiple vulnerabilities have been discovered in HANA Web-based Development Workbench, SAP security note 2153898

SAP Note 2153898

SAP security note 2153898, "Multiple vulnerabilities have been discovered in HANA Web-based Development Workbench", is a note released on 21.05.2015. Below are the symptom and SAP recommended solution.

ComponentSAP HANA > SAP Web IDE for Hana (HAN-WDE)
Released on21.05.2015

Description

Symptom

SQL Injection (CVSS Score 4.9 / 10): allows attackers to modify database commands using specially crafted inputs, leading to data modification. Impact: modification of data persisted by the system.

Reflected Cross Site Scripting (XSS) (CVSS Score 4.3 / 10): enables attackers to modify application content and potentially steal authentication information. Impact: non-permanent defacement or modification of web content; possible theft of user authentication data.

Solution

Update to at least HANA revision 93 (for SPS09) or revision 85.2 (for SPS08).

Reason and prerequisites

An attacker requires a valid user account with the sap.hana.xs.ide.roles::* roles. The impact is limited to the SQL privileges granted to the user.

Full note on SAP: SAP Support Launchpad note 2153898

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More