HotNews
SAP security note 2982840, "Multiple Vulnerabilities in SAP Data Services", is a program error note released on 10.11.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
Remote Code Execution (CVE-2019-0230): SAP Data Services allow an unauthenticated attacker to send a malicious request which could result in remote code execution. This occurs due to insufficient input validation, and a successful exploit would result in complete compromise of system confidentiality, integrity, and availability.
Denial of Service (CVE-2019-0233): SAP Data Services allow an unauthenticated attacker to override access permissions, which may cause Denial of Service when performing a file upload. On successful exploitation, the attacker can completely compromise the availability of the application.
Solution
This correction is delivered in the release(s) listed in the Support Packages and Patches section. Upgrade to the corresponding Support Packages referenced by this SAP Security Note.
CVSS
Score 9.8 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Full note on SAP: SAP Support Launchpad note 2982840
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
