SAP security note 2546220, "[CVE-2017-16691] SNOTE: Digital signature verification vulnerability in note file extraction". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP has released Security Note 2546220 addressing a vulnerability identified as CVE-2017-16691. The issue pertains to the SAP Note Assistant tool, where digital signature verification fails during the extraction of note files from SAR archives if a tampered file is appended. This allows the extraction of unauthorized files despite a failed signature verification.
Solution
The security note enhances the SAP Note Assistant tool by ensuring that the digital signature of the SAR file is verified before extracting the note file. If the verification is successful, the extraction proceeds; otherwise, it fails, preventing the extraction of tampered files.
Reason and prerequisites
SAP Note 2408073 must be implemented in your system.
CVSS
Score 5.3 / 10 Vector: AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected components
- SAP_BASIS 700 to 752
Full note on SAP: SAP Support Launchpad note 2546220
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



