Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2369 Information Disclosure in authentication function of SAP HANA, SAP security note 2572940

SAP Note 2572940

SAP security note 2572940, “[CVE-2018-2369] Information Disclosure in authentication function of SAP HANA”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

UPDATE 19 February 2018: This note has been re-released with updated ‘CVSS Information’.

Under certain conditions, SAP HANA allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory.

Solution

The issue has been fixed with maintenance revision 122.14 (for HANA1 SPS12) and maintenance revision 12.03 (for HANA2 SPS1). Update to these or later revisions. HANA2 SPS2 is not affected.

Reason and prerequisites

The authentication function of SAP HANA contains an error in the memory initialization.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected components

  • HDB 1.00
  • HDB 2.00

Full note on SAP: SAP Support Launchpad note 2572940

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More