SAP security note 2197428, "Potential Remote Code Execution in HANA". Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker with network access to the SQL or Extended Application Services interfaces of SAP HANA could exploit a buffer overflow vulnerability to inject and execute arbitrary code. This could lead to viewing, changing, or deleting data.
Solution
The vulnerability has been fixed in the following revisions:
- SAP HANA 1 SPS10: Revision 102.01
- SAP HANA 1 SPS09: Revision 97.03
Update to the above or later revisions to mitigate this vulnerability. As a temporary workaround, restrict network access to the SQL and Extended Application Services interfaces/ports of the SAP HANA server to trusted applications/users.
CVSS
Score 9.3 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
Full note on SAP: SAP Support Launchpad note 2197428
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



