SAP security note 1964428, "XS bypasses authentication for former public applications", is a program error note released on 11.03.2014. Below are the symptom and SAP recommended solution.
Description
Symptom
An SAP HANA XS based application can be set to be “public” access, meaning that no authentication is needed to access it. In case this configuration setting is changed, authentication is still not enforced.
Solution
The system behavior has been improved with HANA revision 70 (and later). Changes to the authentication setting are now enforced by the system depending on the configured authentication type.
The improvement is also contained in HANA maintenance revision 69.2.
Reason and prerequisites
With the SAP HANA XS administration tool, XS based applications can be configured to be accessible with or without authentication. Changes to a former public application are not considered by the server after changing it to be authenticated.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1964428
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
