SAP security note 2549983, "[CVE-2017-16687] Information Disclosure in SAP HANA XS classic user self-service". Below are the symptom and SAP recommended solution.
Description
Symptom
The user self-service tools of SAP HANA extended application services (XS classic) can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.
Solution
The vulnerabilities have been fixed with the following revisions:
- SAP HANA 1.00 SPS 12: Revision 122.10
- SAP HANA 2.0 SPS 00: Revision 2.02
- SAP HANA 2.0 SPS 01: Revision 12
- SAP HANA 2.0 SPS 02: Initial Revision 020
Update to these or later versions to address the issue.
The system now provides a generic message that does not indicate whether an account exists.
Alternatively, if the user self-service tools are not needed, they can be deactivated as a temporary workaround. By default, the SAP HANA user self-service tool functionality is deactivated, preventing exploitation in this state.
CVSS
Score 5.3 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2549983
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
