PT-2020-16521 · Sap · Sap Business Warehouse+1
Published
2020-12-09
·
Updated
2020-12-11
·
CVE-2020-26838
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Business Warehouse versions 700 through 782
SAP BW4HANA versions 100 through 200
Description
The issue allows an attacker authenticated with high developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. This can result in the execution of Operating System commands, leading to a Code Injection vulnerability that could completely compromise the confidentiality, integrity, and availability of the server and any data or other applications running on it.
Recommendations
For SAP Business Warehouse versions 700 through 782, update to a version that includes the fix for this issue.
For SAP BW4HANA versions 100 through 200, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the system for users with high developer privileges until a patch is available.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Bw/4Hana
Sap Business Warehouse