SAP Security Note
Medium priority
SAP security note 2351486, "Information disclosure in SAP HANA cockpit for offline administration", is a program error note released on 13.12.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A remotely authenticated attacker using the SAP HANA cockpit for offline administration can read files from the server file system with <sid>adm credentials.
Solution
The trace viewer function of the SAP HANA cockpit for offline administration has been limited to files in the trace folders. Other files are no longer displayed.
Additionally, some error messages have been improved to contain only relevant information.
These improvements are included in:
- SAP HANA Revision 112.06 (for SPS11)
- SAP HANA Revision 122.02 (for SPS12)
Update to these or later revisions.
Additional recommendations:
- The <sid>adm user is a highly privileged account with access to all server-local resources. Ensure that only administrators know these credentials.
- Restrict access to the SAP HANA cockpit for offline administration to trusted administrators only.
Reason and prerequisites
The SAP HANA cockpit for offline administration allows access to selected administrative functions of the SAP HANA system. A prerequisite for access is knowing the username and password of the operating system user of the SAP HANA system (<sid>adm user).
A specially crafted request can allow a user/attacker to display the content of other files on the server.
CVSS
Score 4.9 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected components
- HDB 1.00
Full note on SAP: SAP Support Launchpad note 2351486
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




