SAP security note 1498368, “Credit Card Data Leakage in SAP POS Solutions”, is a note released on December 14, 2010. Below is the security information published by SAP for this note.
Description
Overview
A critical security vulnerability has been identified in SAP POS systems where credit card information is not properly cleared from the hard disk after transactions. This issue violates the Payment Card Industry (PCI) Data Security Standard, posing significant risks to retailers using SAP POS solutions.
Impact
Sensitive credit card data may remain on the hard disk in plain text, leading to potential data breaches and non-compliance with PCI standards.
Solution
SAP has released updates for SAP POS v2.1 and v2.2 to fix this issue. Users should contact Active Global Support to obtain the necessary patches.
Workaround
As a temporary measure, consider using a separate terminal and avoid integrated EFT solutions with SAP POS. Ensure that your POS environment is secure to prevent unauthorized access.
Additional information
The issue was caused by memory leaks that prevented the clearing of credit card information from memory. The fix addresses these memory leaks across various components of the SAP POS system.
For more information, visit the SAP Note 1498368.
Full note on SAP: SAP Support Launchpad note 1498368
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
