Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to passwords in SAP Web Dispatcher trace files, SAP security note 2148905

SAP Note 2148905

SAP security note 2148905, “Potential information disclosure relating to passwords in SAP Web Dispatcher trace files”, is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can discover information relating to passwords through the SAP Web Dispatcher. This information could be used to allow the attacker to specialize their attacks against SAP HANA Database or SAP HANA Extended Application Services.

The issue affects both the standalone SAP Web Dispatcher and the internal HANA Web Dispatcher.

Solution

The Web Dispatcher trace function has been improved to suppress all passwords related to SAP HANA Extended Application Services.

  • For the standalone SAP Web Dispatcher, apply the Kernel patch referenced in this SAP Note.
  • For the internal HANA Web Dispatcher, apply SAP HANA SPS 9 Database Revision 97 or higher.

Workaround / Mitigating Measures

  • Use HTTPS: HTTPS should be used as much as possible. If HTTPS is used, request bodies are not logged to the Web Dispatcher trace file.
  • Restrict Access to Trace Files: Trace files can contain sensitive information. It is recommended that access authorizations to trace files are handled carefully.
  • Restrict Trace Level Changes: Authorizations to increase the trace level should be assigned restrictively. In SPS 8 (and lower), only the operating system user sidadm can change the Web Dispatcher trace level. In SPS 9 (and higher), the system privilege INIFILEADMIN or the role sap.hana.xs.wdisp.admin::WebDispatcherAdmin is required.

Reason and prerequisites

Information is logged to the trace files of the Web Dispatcher if it is configured. If the trace level is set to a higher trace level, this information includes sensitive information such as user passwords. This information may be used by an attacker to further target SAP HANA.

CVSS

Score 1.5 Vector: AV:L/AC:M/Au:S/C:P/I:N/A:N

Affected components

  • SAP HANA > SAP HANA Application Services > SAP HANA Extended Application Services

Full note on SAP: SAP Support Launchpad note 2148905

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More