Release date: 2011-11-11
Updated on: 2011-11-23
Affected Systems:
SAP NetWeaver
Description:
--------------------------------------------------------------------------------
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
TH_GREP reports that a remote security vulnerability exists in implementation, which can lead to illegal execution of OS commands.
<* Source: Alexey Tyurin
Link: http://erpscan.com/advisories/dsecrg-11-039-sap-netweaver-th_grep-module-code-injection-vulnerabilit
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
SAP has released a Security Bulletin (DSECRG-11-039) and patches for this:
DSECRG-11-039: SAP NetWeaver TH_GREP Module-Code Injection Vulnerability (NEW)
Link: http://erpscan.com/advisories/dsecrg-11-039-sap-netweaver-th_grep-module-code-injection-vulnerabilit