SAP security note 2572940, “[CVE-2018-2369] Information Disclosure in authentication function of SAP HANA”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 19 February 2018: This note has been re-released with updated ‘CVSS Information’.
Under certain conditions, SAP HANA allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory.
Solution
The issue has been fixed with maintenance revision 122.14 (for HANA1 SPS12) and maintenance revision 12.03 (for HANA2 SPS1). Update to these or later revisions. HANA2 SPS2 is not affected.
Reason and prerequisites
The authentication function of SAP HANA contains an error in the memory initialization.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected components
- HDB 1.00
- HDB 2.00
Full note on SAP: SAP Support Launchpad note 2572940
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



