SAP ERP BW Business Content OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in SAP ERP BW Business Content, specifically within certain function modules. When these modules are executed with elevated privileges, they inadequately validate user input, enabling attackers to inject and execute arbitrary operating system commands. This flaw significantly jeopardizes the application's security by allowing unintended command execution on the underlying system.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of operating system commands, potentially allowing attackers to manipulate the underlying system or application environment in harmful ways.

Remediation

Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, where all Security Notes are available. It is recommended to implement these security corrections as a priority.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
4.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.