SAP security note 2233550, “Communication encryption for HANA multi tenant database containers does not work as expected”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The communication encryption in the SAP HANA multi tenant database container feature does not work as expected. Specifically, in SAP HANA revisions 100-102.01 (SPS10), an error in the implementation results in no authentication/encryption being performed for tenant services in "high isolation" mode. This affects only the communication within the services of a tenant and the cross-database access in a SAP HANA multi tenant database container system. If TLS/SSL protection for internal communication is enabled (parameter [communication] SSL is set to systemPKI), communication among tenant services will be encrypted, but there is no protection against unauthorized connections by other tenants on the same database. Other communication channels of the SAP HANA system are not affected.
Solution
The issue has been fixed with revision 102.02. It is recommended to update to this or later revisions.
SAP HANA SPS11 is not affected. SAP HANA systems in single tenant mode (without SAP HANA multi tenant database container installation) are not affected.
CVSS
Score 5.8 Vector: AV:A/AC:H/Au:N/C:C/I:P/A:P
Affected components
- HDB 1.00 to 1.00
Full note on SAP: SAP Support Launchpad note 2233550
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
