SAP security note 2067859, “Potential Exposure to Digital Signature Spoofing”. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can misuse versions of SAP Cryptographic Libraries used by SAP NetWeaver Application Server (SAP NetWeaver AS) for ABAP and SAP HANA applications to spoof digital signatures.
Solution
Replace the affected libraries.
- If you are using SAPCRYPTOLIB, upgrade to version 5.5.5.38 or later.
- If you are using SAPSECULIB, upgrade to SAPCRYPTOLIB version 5.5.5.38 or later. Refer to the necessary actions described in section 1 and 2 of Note 510007.
- If you are using CommonCryptoLib, upgrade to version 8.4.30 or later.
SAP recommends always upgrading to the latest version of the respective library.
Option 1, Manual Replacement: for more information on how to replace the SAP Cryptographic Library for AS for ABAP and SAP HANA, see the PDF attached to this note. You can download the SAP Cryptographic Library from the SAP Software Download Center.
Option 2, Automatic Replacement via Kernel Update (AS for ABAP only): SAP recommends replacing SAPCRYPTOLIB and SAPSECULIB with the latest version of the CommonCryptoLib. Refer to Note 1848999 for prerequisites and detailed information about updating to CommonCryptoLib. The following stack kernel patch levels include the fixed CommonCryptoLib: 720 PL#700 and 741 PL#100.
Note: even though PL#712 is listed for kernel 720, the correction is also included in 720 PL#700. The same applies to PL#741, where PL#110 is listed, but 741 PL#100 also contains the correction.
As an additional security measure, replace the DSA PSEs on all impacted SAP NetWeaver Application Server ABAP and SAP HANA systems and the corresponding system public keys in their signature trust systems. For more information, see Note 2068693.
Reason and prerequisites
There is a critical vulnerability in versions of SAPCRYPTOLIB, SAPSECULIB, and CommonCryptoLib components of SAP NetWeaver AS for ABAP and SAP HANA applications. The vulnerability may enable an attacker to spoof system digital signatures based on the DSA algorithm. The issue impacts logon tickets, authentication assertion tickets, and other applications that use SAP NetWeaver AS for ABAP and SAP HANA system-generated digital signatures.
References
- 2068693 – Replacing Key Pairs in SAP NetWeaver Application Server for ABAP and SAP HANA Platform Systems
- 1848999 – Central Note for CommonCryptoLib 8 (SAPCRYPTOLIB)
- 510007 – Additional considerations about setting up SSL on Application Server ABAP
Full note on SAP: SAP Support Launchpad note 2067859
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
