SAP Security Note
Low priority
SAP security note 2428811, "SQL Injection Vulnerability in SAP HANA Web Workbench", is a program error note released on March 14, 2017. Below are the symptom and SAP recommended solution.
Description
Symptom
The SAP HANA Web Workbench allows an authenticated user to execute crafted database queries. These queries can manipulate settings in the performance_analyzer section of the global.ini file. The SQL commands execute with the privileges of the calling user, and privilege escalation is not possible.
Solution
The issue has been fixed in the following revisions:
- SAP HANA 1.00 SPS 12: Revision 122.06
- SAP HANA 2.0 SPS 00: Revision 001
Update to these or later versions to resolve the vulnerability.
Reason and prerequisites
User must have been granted the following privileges:
- TRACE ADMIN
- INIFILE ADMIN
CVSS
Score 2.7/10 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2428811
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
