SAP security note 1418031, "Potential Security Issues in SAP Solution Manager", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP Note addresses security issues in the Implementation part of SAP Solution Manager (component SV-SMG-IMP*). The following risks are mitigated:
Cross Site Scripting (XSS): Malicious users can exploit XSS vulnerabilities to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
SQL Injection: Specially crafted inputs can allow malicious users to execute arbitrary database commands, enabling them to retrieve, modify, or delete data stored by the system.
Hard-coded User Names (Backdoor): The system contains hard-coded usernames that alter the program’s behavior upon successful authentication, potentially allowing unauthorized access to sensitive information.
Solution
Implement this SAP Note via Note Assistant (transaction SNOTE).
References
- 1418032 – Potential Security Issues in SAP Solution Manager
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SAP Solution Manager ST400
Full note on SAP: SAP Support Launchpad note 1418031
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
