SAP security note 2028484, “Missing Authorization Check in SQL Processing in HANA”, is a program error note released on August 12, 2014. Below is the security information published by SAP for this note.
Description
Symptom
An authenticated user can use functions of SAP HANA to access data without having the necessary authorization.
Reason and prerequisites
SAP HANA does not contain appropriate authorization checks for verifying an authenticated user's permission to access certain data. This vulnerability can be exploited to read data by authenticated users capable of executing SQL commands.
Solution
The issue has been fixed with:
- HANA revision 81 (for SPS08)
- HANA revision 74.3 (for SPS07)
Action Required: Update your SAP HANA system to at least these versions to mitigate the vulnerability.
Additional information
- Component: SAP HANA Database (HAN-DB)
- Priority: Correction with high priority
- Status: Released for Customer
- Category: Program error
—
Credits to redrays.io for support to provided information. “`
Full note on SAP: SAP Support Launchpad note 2028484
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
