Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential log injection vulnerability in SAP HANA Extended Application Services, SAP security note 2109818

SAP Note 2109818

SAP security note 2109818, "Potential log injection vulnerability in SAP HANA Extended Application Services". Below are the symptom and SAP recommended solution.

Description

Symptom

A potential attacker can inject arbitrary lines into the log of the SAP HANA Extended Application Services (HANA XS).

Solution

The log writing function has been improved with SAP HANA SPS09, revision 90. Update to revision 90 or later.

Reason and prerequisites

A potential attacker might be able to inject additional lines into the HANA XS log via specially crafted HTTP requests. These forged additional line entries might confuse users analyzing these logs.

Existing data cannot be changed or read by this potential vulnerability.

CVSS

Score 4.0 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Full note on SAP: SAP Support Launchpad note 2109818

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More