Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

OS CMD injection vulnerability in ST-PI, SAP security note 1861791

SAP Note 1861791
SAP Security Note
High priority

SAP security note 1861791, "OS CMD Injection Vulnerability in ST-PI", is a program error note released on 10.12.2013. Below are the symptom and SAP recommended solution.

ComponentService > SAP Solution Manager > Service Data Download
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on10.12.2013
LanguageEnglish

Description

Symptom

Software component ST-PI contains code that permits the execution of an OS command that is up to 7 characters long.

Solution

Implement the attached coding correction or import ST-PI 2008_1_XXX SP8. The possibility to execute an OS command will be deactivated by this measure.

Reason and prerequisites

The program code contains a possibility to define and execute one user-defined OS command that has a length of up to 7 characters.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

References

Full note on SAP: SAP Support Launchpad note 1861791

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More