Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 2902456
was released on
14.04.2020 and deals with
"[CVE-2020-6236] Privilege Escalation in SAP Landscape Management (SAP Adaptive Extensions)" within SAP Landscape Management.
We advice you to follow the instructions, to resolve
command injection
with a
high potential for exploitation
in component BC-VCM-LVM.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
An authenticated attacker might be able to execute arbitary commands with root privileges on a target system.Solution
SAP Landscape validation will now properly validates user input.
- 9.9 [CVE-2021-38163] Unrestricted File Upload vulnerability in SAP NetWeaver (Visual Composer 7.0 RT)
- 7.2 [CVE-2020-6191] Missing Input Validation in SAP Landscape Management
- 7.2 [CVE-2020-6192] Missing Input Validation in SAP Landscape Management
- 7.2 [CVE-2020-6234] Privilege Escalation in SAP Host Agent
- 6.5 [CVE-2021-38180] CSV Injection in SAP Business One