SAP security note 1450529, "Potential Security Issues in Service Session Workbench", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Service Session Workbench in SAP Solution Manager (component SV-SMG-SVD-SWB) has vulnerabilities that could be exploited to execute arbitrary database commands or alter system behavior.
- SQL Injection: allows malicious users to manipulate SQL statements to retrieve, modify, or delete data.
- Hard-coded User Names (Backdoor): enables unauthorized behavior changes when specific usernames are used for authentication.
Solution
To mitigate these vulnerabilities, install the corresponding support package or implement this SAP Note via Note Assistant (transaction SNOTE).
- Fixed Versions and Patch Levels: ST400 SP23
Affected components
- SAP Solution Manager ST400
Full note on SAP: SAP Support Launchpad note 1450529
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
