SAP security note 1434117, "Bypassing sec_info without reg_info", released on August 26, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Without setting the gw/reg_info parameter (applicable up to and including Kernel Release 7.11), the system uses only the gw/sec_info file to manage both restarting and registering programs. This may enable the restarting of external programs without proper security validations.
Solution
To mitigate this security gap, perform the following actions:
- Apply relevant patch levels: 31I_EXT patch level 785, 40B_EXT patch level 1074, 45B_EXT patch level 1005.
- Configure instance profile parameter: set gw/reg_no_conn_info as specified in Note 1444282 based on your target security level.
- Update sec_info and reg_info files: for Kernel Releases 31I to 46D, perform manual post-implementation steps to update the sec_info file; for Kernel Release 640 and higher, create separate sec_info and reg_info files to define restarting and registering programs independently.
- Ensure proper configuration: when gw/reg_no_conn_info is set, registrations cannot be performed without the reg_info file defined by gw/reg_info.
Reason and prerequisites
The issue is caused by a kernel error that fails to separate the rules for restarting and registering programs when gw/reg_info is not configured.
References
- Note 1465129 – CANCEL registered programs
- Note 1444282 – gw/reg_no_conn_info settings
- Note 1298433 – Bypassing security in reginfo & secinfo
Affected components
- SAP Kernel 31I
- SAP Kernel 40B
- SAP Kernel 45B
- SAP Kernel 46D
- SAP Kernel 640
- SAP Kernel 700 to 730
- SAP Kernel 7.00 to 7.20
Full note on SAP: SAP Support Launchpad note 1434117
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
