Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Log Viewer mishandles system credentials, SAP security note 2240946

SAP Note 2240946
SAP Security Note
Medium priority

SAP security note 2240946, “Log Viewer mishandles system credentials”, is a program error note released on 08.12.2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Local Admin Tools > Logging
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on08.12.2015
LanguageEnglish

Description

Symptom

The Log Viewer component can be exploited by an attacker with Administrator credentials to obtain Operating System access to the machine where the SAP NetWeaver server is installed.

Solution

Apply the appropriate support package available in the SP Patch Level tab of this SAP note. For detailed information on affected releases and patch levels, refer to the Support Package Patches section of the note.

For more information about the SP Stack schedule and updates, visit the SP Stacks maintenance schedule.

Reason and prerequisites

A coding error in the Log Viewer component allows for the mishandling of system credentials.

CVSS

Score 4.6 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P

References

Full note on SAP: SAP Support Launchpad note 2240946

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More