SAP security note 2109818, "Potential log injection vulnerability in SAP HANA Extended Application Services". Below are the symptom and SAP recommended solution.
Description
Symptom
A potential attacker can inject arbitrary lines into the log of the SAP HANA Extended Application Services (HANA XS).
Solution
The log writing function has been improved with SAP HANA SPS09, revision 90. Update to revision 90 or later.
Reason and prerequisites
A potential attacker might be able to inject additional lines into the HANA XS log via specially crafted HTTP requests. These forged additional line entries might confuse users analyzing these logs.
Existing data cannot be changed or read by this potential vulnerability.
CVSS
Score 4.0 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N
Full note on SAP: SAP Support Launchpad note 2109818
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
