SAP security note 1823566, “Potential information disclosure relating to SolutionManager”. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to passwords who uses SAP Solution Manager. This information could be used to allow the attacker to specialize their attacks against server information and processes and the SAP database.
Solution
The correction provided by this note migrates database connection information created by old versions of SAP Solution Manager into the new storage model, i.e., separation of user and connection information apart from password. The solution requires a specific kernel (disp+work) patch level and ABAP support package. Please apply the levels as mentioned in this note; for ABAP you may apply the correction instruction instead. After the implementation, you have to execute report RS_DBC_CLEANUP, which performs the migration. For the execution of this report the authorization S_RZL_ADM with ACTVT = ’01’ is needed.
Reason and prerequisites
Information such as the landscape configuration data and database user passwords can be discovered using SAP Solution Manager. This information may be used by an attacker to further target SAP database. Note that the user and password for database connections created in old versions of SAP Solution Manager are stored in table DBCON instead of separation of the user and connection information apart from the password. These information is kept and may have been residing in your system for ages.
CVSS
Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N
References
This note refers to
Referenced by
Full note on SAP: SAP Support Launchpad note 1823566
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
