Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information disclosure in the CCMS agent of SAP HANA, SAP security note 2347944

SAP Note 2347944

SAP security note 2347944, "Information disclosure in the CCMS agent of SAP HANA". Below are the symptom, SAP recommended solution, reason and prerequisites, CVSS score and references.

Description

Symptom

SAP HANA installs the SAP Host Agent, containing the SAP CCMS (Computer Center Management System) agent component. This agent enables central system monitoring. The CCMS web method GetAgentConfig is used in CCMS central monitoring to test the configuration of CCMS agents running on a monitored system.

A remote unauthenticated attacker can find out the host name and the version of the CCMS agent. Note that no data of (or about) the SAP HANA database or any other HANA components is disclosed.

Solution

SAP Host Agent 7.21 patch level 16 introduces authentication for the method GetAgentConfig. The SAP Host Agent of the SAP HANA system can be updated independently of the other system components. Update to patch level 16 or higher of SAP Host Agent 7.21.

SAP HANA revision 112.05 (for SPS11) and SAP HANA revision 122 (for SPS12) contain this SAP Host Agent version by default.

Find more information about the improvement in SAP Note 2306739.

Reason and prerequisites

Potential attackers need network access to port 1128 of the SAP HANA system to contact the CCMS agent.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

  • SAP Note 2306739 – Optimization of authorization concept of SAPCCMS web method GetAgentConfig

Full note on SAP: SAP Support Launchpad note 2347944

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More