SAP Security Note
HotNews
SAP security note 2424173, "Vulnerabilities in the user self-service tools of SAP HANA", is a program error note released on March 14, 2017. Below are the symptom and SAP recommended solution.
Description
Symptom
The user self-service tools of SAP HANA contain vulnerabilities that could allow an unauthenticated user to impersonate other users, including administrative accounts. It is highly recommended to either update to the latest revisions or deactivate the user self-service tools.
Solution
The vulnerabilities have been fixed with:
- Revision 122.07 for SAP HANA 1.00 SPS 12
- Revision 001 for SAP HANA 2.0 SPS 00
Update: apply the above revisions or later versions to mitigate the vulnerabilities. Deactivate: if the user self-service tools are not needed, consider deactivating them as a temporary workaround. By default, the SAP HANA user self-service tool functionality is deactivated, and the vulnerabilities cannot be exploited in this state.
To check if the user self-service tool is active, execute the following SQL query: SELECT NAME, STATUS FROM "_SYS_XS"."SQL_CONNECTIONS" WHERE NAME = ‘sap.hana.xs.selfService.user::selfService’. If activated and not needed, deactivate it via the SAP HANA XS Admin interface.
CVSS
Score 9.80/10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Full note on SAP: SAP Support Launchpad note 2424173
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
