Advisory
A note with CVSS 9.1 for component BC-DB-ODB was released by SAP on 14.04.2020. The correction/advisory 2900118 was described with "[CVE-2020-6230] Code Injection vulnerability in SAP OrientDB 3.0" and affects the system type SAP Orient DB.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is code injection within SAP Orient DB.
Risk specification
SAP OrientDB 3.0 allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the application and lead to an elevation of privileges. An attacker could thereby control the behavior of the application.Solution
A new parameter was added to restrict access to system level functionality.
The advisory is valid for
- ORIENTDB 3.0
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
- 10.0 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition