SAP Security Note
High priority
SAP security note 1861791, "OS CMD Injection Vulnerability in ST-PI", is a program error note released on 10.12.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
Software component ST-PI contains code that permits the execution of an OS command that is up to 7 characters long.
Solution
Implement the attached coding correction or import ST-PI 2008_1_XXX SP8. The possibility to execute an OS command will be deactivated by this measure.
Reason and prerequisites
The program code contains a possibility to define and execute one user-defined OS command that has a length of up to 7 characters.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
References
Full note on SAP: SAP Support Launchpad note 1861791
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
