Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential remote code execution in HANA, SAP security note 2197428

SAP Note 2197428

SAP security note 2197428, "Potential Remote Code Execution in HANA". Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker with network access to the SQL or Extended Application Services interfaces of SAP HANA could exploit a buffer overflow vulnerability to inject and execute arbitrary code. This could lead to viewing, changing, or deleting data.

Solution

The vulnerability has been fixed in the following revisions:

  • SAP HANA 1 SPS10: Revision 102.01
  • SAP HANA 1 SPS09: Revision 97.03

Update to the above or later revisions to mitigate this vulnerability. As a temporary workaround, restrict network access to the SQL and Extended Application Services interfaces/ports of the SAP HANA server to trusted applications/users.

CVSS

Score 9.3 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Full note on SAP: SAP Support Launchpad note 2197428

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More