Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential log injection vulnerability in SAP HANA audit log, SAP security note 2197459

SAP Note 2197459

SAP security note 2197459, "Potential log injection vulnerability in SAP HANA audit log". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A potential attacker can inject arbitrary fields into the audit log of the SAP HANA server. This vulnerability allows the injection of additional field entries via specially crafted requests, which might confuse users analyzing these logs. Note: Existing data cannot be changed or read by this potential vulnerability.

Solution

The log writing function has been improved in the following SAP HANA revisions. It is recommended to update to these or later revisions to mitigate the vulnerability:

  • Revision 85.05 (for SPS08)
  • Revision 97.02 (for SPS09)
  • Revision 102 (for SPS10)

CVSS

Score 5.0 / 10 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected components

  • SAP HANA Database (HAN-DB): Affected Versions 1.00

Full note on SAP: SAP Support Launchpad note 2197459

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More