SAP security note 1298433, “Bypassing security in reginfo & secinfo”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
- Unauthorized programs can communicate with the SAP gateway by bypassing reginfo and secinfo settings.
- This affects kernel release 701 and certain other releases as detailed in the note.
Solution
Workaround:
If immediate correction is not feasible, enhance system protection by:
- Implementing a firewall to restrict connections to the SAP gateway to only trusted hosts.
- Ensuring all connections to the gateway from remote hosts are secured using Secure Network Communication (SNC). This can be achieved by:
- Using connections between two SAProuters secured via SNC for the WAN segment.
- Utilizing a Virtual Private Network (VPN) tunnel to secure the WAN segment.
Error correction:
- Apply kernel patch: update to the highest relevant kernel patch as specified in the “Support Package” section of the note.
- Set instance profile parameter: configure the parameter gw/reg_no_conn_info in the instance profile to activate enhanced security. For detailed instructions, refer to Note 1444282.
Patch levels required for kernel releases 31I-45B:
- 31I: SP Patch 784
- 40B: SP Patch 1073
- 45B: SP Patch 1004
For information on downloading Kernel Releases 31I-45B, see Note 52505: Support after end of mainstream/extended maintenance.
From Kernel Release 710 onwards, enhanced security is active by default. Patches include improvements for monitoring in transaction SMGW. Dynamic parameter changes can be made using the function module TH_CHANGE_PARAMETER if necessary.
Reason and prerequisites
A program error in the kernel allows the bypassing of security settings in reginfo and secinfo files. For security reasons, detailed information about the error is not disclosed.
References
Affected components
- Kernel Releases 31I-45B (BC-CST-GW)
Full note on SAP: SAP Support Launchpad note 1298433
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
