Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2017-16691 SNOTE Digital signature verification along with note file extraction, SAP security note 2546220

SAP Note 2546220

SAP security note 2546220, "[CVE-2017-16691] SNOTE: Digital signature verification vulnerability in note file extraction". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP has released Security Note 2546220 addressing a vulnerability identified as CVE-2017-16691. The issue pertains to the SAP Note Assistant tool, where digital signature verification fails during the extraction of note files from SAR archives if a tampered file is appended. This allows the extraction of unauthorized files despite a failed signature verification.

Solution

The security note enhances the SAP Note Assistant tool by ensuring that the digital signature of the SAR file is verified before extracting the note file. If the verification is successful, the extraction proceeds; otherwise, it fails, preventing the extraction of tampered files.

Reason and prerequisites

SAP Note 2408073 must be implemented in your system.

CVSS

Score 5.3 / 10 Vector: AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected components

  • SAP_BASIS 700 to 752

Full note on SAP: SAP Support Launchpad note 2546220

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More