SAP security note 2278931, "Update 1 to 1906212: Code injection vulnerability in Knowledge Provider.", was released on January 9, 2018. Below are the symptom and SAP recommended solution.
Description
Symptom
This security note addresses a code injection vulnerability in the BC-SRV-KPR-DMS component of SAP. The vulnerability allows a malicious user to execute arbitrary program code, potentially controlling system behavior or escalating privileges without legitimate credentials.
Solution
Implement this SAP Note or upgrade to the relevant Support Packages listed below. For a complete fix, also implement SAP Note 2525392.
CVSS
Score 6.5 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
References
This note refers to
Full note on SAP: SAP Support Launchpad note 2278931
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




