SAP Security Note
High priority
SAP security note 1623922, "Connect to Oracle Database", is a consulting note released on November 7, 2011. Below are the symptom, SAP recommended solution and references.
Description
Symptom
A vulnerability has been identified in the SAP connection to the Oracle database using the OPS$ method. This vulnerability allows a malicious user to log on to the database as an OPS$ user without entering a password unless appropriate measures are taken.
The connection to the Oracle database using the OPS$ method contains a vulnerability that permits unauthorized access without a password.
Solution
- For SAP kernel versions up to 7.11 and Oracle up to 11.2: Follow the procedures outlined in Note 157499 "OPS$- security risks and minimization".
- For SAP kernel version 7.20 and above: Utilize the Secure Store (SSFS) for password storage, eliminating the need for the OPS$ connect. Refer to Note 1639578 for general configuration and Note 1622837 "Connect to Oracle via SSFS (Secure Store)" for Oracle-specific steps.
Connection methods overview:
- Versions 4.6D, 6.40, 7.00 to 7.11: Use the OPS$ method.
- Version 7.20 (patch 100) and higher with Oracle 10/11: OPS$ method or Secure Store (recommended).
- Oracle 12 and higher: Secure Store method recommended.
Reason and prerequisites
Up to SAP kernel version 7.11 and Oracle up to version 11.2, the SAP database user’s password is stored encrypted in a table accessible only by the OPS$ user. Without secure measures, this can be exploited.
References
- Note 700548: FAQ: Oracle authorizations
- Note 1868094: Overview: Oracle Security SAP Notes
- Note 1487754
Full note on SAP: SAP Support Launchpad note 1623922
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




