Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Multiple security vulnerabilities in SDM, SAP security note 1724516

SAP Note 1724516

SAP security note 1724516, “Multiple security vulnerabilities in SDM”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can disclose information related to AS Java by exploiting the Software Deployment Manager (SDM). This information could be used to initiate specialized attacks against AS Java and SDM.

An attacker can remotely exploit SDM to render it unavailable, potentially affecting the resources that serve SDM.

Solution

  • Update SDM: Update the SDM server and the SDM client API to a Support Package (SP) or release where the issue is fixed. Refer to the SP Patch Level section of this SAP Note 1724516 for details and available patches.
  • Enable Security Features: Enable the security features of SDM by following the instructions in the attached SDM_EnablingSecurity.pdf.

Reason and prerequisites

Information about installed products, their versions, data, and user passwords can be disclosed using SDM. This information might be leveraged by an attacker to further target AS Java.

An attacker can send a specifically crafted request to cause the SDM server to shut down, leading to a denial of service on AS Java.

CVSS

Score 4.9 Vector: AV:A/AC:M/AU:S/C:P/I:P/A:P

References

Affected components

  • JSPM: Versions 7.00 to 7.02
  • SAP_JAVAEU: Version 2.0 and 7.00 to 7.02
  • SAP_JAVASL: Versions 7.00 to 7.02
  • SAP-JEE: Version 6.40
  • SAP_JTECHS: Versions 7.00 to 7.02
  • SAP_DEVINF: Version 6.40
  • NWCEIDE: Versions 7.10 to 7.31
  • SERVERCORE: Versions 7.10 to 7.31

Full note on SAP: SAP Support Launchpad note 1724516

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More