SAP security note 2565622, “[CVE-2018-2368] Missing Authentication check in SAP NetWeaver System Landscape Directory”. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP NetWeaver System Landscape Directory does not perform any authentication checks for functionalities that require user identity.
Some well-known impacts of missing authentication checks include:
- Read, modify, or delete sensitive information
- Access administrative or other privileged functionalities
Solution
Additional authentication checks are implemented. Implement the Support Packages and Patches referenced by this SAP Note.
Reason and prerequisites
JNDI does not require authentication.
CVSS
Score 8.3 Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
References
Referenced by
- 2566930: Collective Note: SAP NetWeaver 7.30 SP18 – NWDS Update Site standalone
- 2567013: Collective Note: SAP NetWeaver 7.30 SP18 – Application Server Java
- 2637693: Central note for SAP NetWeaver 7.31 SP23 Application Server Java
- 2576877: ABAP system fails to connect to AS Java SLD with error "User credentials are invalid or user is denied access"
Full note on SAP: SAP Support Launchpad note 2565622
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
