Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XS bypasses authentication for former public applications, SAP security note 1964428

SAP Note 1964428SAP Security NoteHigh priority

SAP security note 1964428, "XS bypasses authentication for former public applications", is a program error note released on 11.03.2014. Below are the symptom and SAP recommended solution.

ComponentSAP HANA > SAP HANA Application Services > SAP HANA Extended Application Services
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on11.03.2014
LanguageEnglish

Description

Symptom

An SAP HANA XS based application can be set to be “public” access, meaning that no authentication is needed to access it. In case this configuration setting is changed, authentication is still not enforced.

Solution

The system behavior has been improved with HANA revision 70 (and later). Changes to the authentication setting are now enforced by the system depending on the configured authentication type.

The improvement is also contained in HANA maintenance revision 69.2.

Reason and prerequisites

With the SAP HANA XS administration tool, XS based applications can be configured to be accessible with or without authentication. Changes to a former public application are not considered by the server after changing it to be authenticated.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 1964428

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More