SAP security note 1396998, "Log Viewer Server ports should be protected by firewall", is a customizing note released on 08.06.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
The Log Viewer Server prints a warning that it is not protected by authorization checks; this allows logs to be monitored or spied. We strongly recommend that you configure your firewall to allow connections on port 1099 and 26000 only, from a dedicated SMD host or administrative systems.
Solution
Configure your firewall to allow connections on the ports mentioned above only from a dedicated SMD host or administrative systems.
Reason and prerequisites
Access to ports 1099 (default port for JNDI) and 26000 (default port for Log Viewer NI connection) is not protected by authorization checks. This allows logs to be monitored by any Log Viewer client. Whenever access to log files is perceived as a security threat, it is strongly recommended to restrict connections to the Log Viewer Server based on firewall rules or routing configuration. Port numbers are configurable in <j2ee>/admin/logviewer-standalone/server/LogViewerServer.properties by modifying the values of the keys Logviewer_java.naming.provider.url and Logviewer_NI_port.
Full note on SAP: SAP Support Launchpad note 1396998
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



