SAP security note 2408073, "Handling of Digitally Signed notes in SAP Note Assistant", is a program error note released on 16.01.2018. Below are the symptom, CVSS score and the affected software components.
Description
Symptom
UPDATE 16th January 2018: this note has been re-released with updated "Solution" and "References" information. UPDATE 16th November 2017: this note has been re-released with updated "Manual correction instruction" information. UPDATE 16th October 2017: this note has been re-released with updated "correction instructions" and "Manual Activities" information.
Prepare your system to be able to upload digitally signed SAP Notes. When SAP switches to deliver digitally signed SAP Notes from SAP Support Portal, the SNOTE tool should be enabled to upload digitally signed SAP Notes.
For SAP_BASIS releases below 700, there are no automatic correction instructions available. To enable the SNOTE tool to upload digitally signed SAP Notes, you have to perform manual activities for every SAP Note that needs to be applied. Perform the manual activities as described in this SAP Note for SAP_BASIS releases below 700.
CVSS
Score 5.5/10 Vector: AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
References
This note refers to
- 2377859 – SAPCAR: error in loading the cryptographic library (error 56) during upload of Archives in SPAM
- 2234938 – SPAM SAINT error: SAPCAR: could not open for writing /usr/sap/trans/SIGNATURE.SMF (error 28)
- 2576306 – Transport-Based Correction Instruction (TCI) for Download of Digitally Signed SAP Notes
- 2546220 – [CVE-2017-16691] SNOTE: Digital signature verification along with note file extraction
- 2537133 – FAQ – Digitally Signed SAP Notes
- 2508268 – Download of Digitally Signed SAP Notes in SNOTE
- 2178665 – Signature validation of archives with SAPCAR
- 1634894 – SAPCAR: Signed Archive
Affected components
- SAP_BASIS 46A to 46D
- SAP_BASIS 610 to 640
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 711
- SAP_BASIS 730
- SAP_BASIS 731
- SAP_BASIS 740
- SAP_BASIS 750 to 752
Full note on SAP: SAP Support Launchpad note 2408073
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
