Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to passwords LDAP, SAP security note 1820305

SAP Note 1820305

SAP security note 1820305, "Potential Information Disclosure Relating to Passwords: LDAP", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker may exploit this vulnerability to access password information of LDAP directory servers, facilitating more targeted and effective attacks.

Solution

A support package or correction request is available to mitigate this issue. Specifically, the maintenance of the "LDAP System User" (LDAPUSER) now restricts the selection of "Credential storage = Simple Memory." For entries previously using this option, a warning is displayed in the "Display View ‘LDAP System User’: Details" screen. To resolve:

  • Enter edit mode for the LDAP system user.
  • Switch from "Simple Memory" to "Secure Storage."
  • Upon saving, the password is transferred to secure storage, and the simple memory entry is deleted.

Reason and prerequisites

Sensitive information, such as LDAP directory server passwords, can be retrieved through a database table lookup. This compromised information can be used by attackers to further target and breach LDAP directory servers.

References

Affected components

  • SAP_BASIS 700 to 740

Full note on SAP: SAP Support Launchpad note 1820305

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More