Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Multiple Vulnerabilities in SAP Data Services, SAP security note 2982840

SAP Note 2982840
HotNews

SAP security note 2982840, "Multiple Vulnerabilities in SAP Data Services", is a program error note released on 10.11.2020. Below are the symptom and SAP recommended solution.

ComponentEnterprise information management solutions > Data Services > Deployment, Installation, Upgrade (EIM-DS-DEP)
CategoryProgram error
PriorityHotNews
Version5
StatusReleased for Customer
Released on10.11.2020
LanguageEnglish

Description

Symptom

Remote Code Execution (CVE-2019-0230): SAP Data Services allow an unauthenticated attacker to send a malicious request which could result in remote code execution. This occurs due to insufficient input validation, and a successful exploit would result in complete compromise of system confidentiality, integrity, and availability.

Denial of Service (CVE-2019-0233): SAP Data Services allow an unauthenticated attacker to override access permissions, which may cause Denial of Service when performing a file upload. On successful exploitation, the attacker can completely compromise the availability of the application.

Solution

This correction is delivered in the release(s) listed in the Support Packages and Patches section. Upgrade to the corresponding Support Packages referenced by this SAP Security Note.

CVSS

Score 9.8 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Full note on SAP: SAP Support Launchpad note 2982840

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More