SAP security note 2587369, "[CVE-2018-2402] Potential information disclosure in SAP HANA capture & replay trace file", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
In systems utilizing the optional capture & replay functionality of SAP HANA, there is a vulnerability where user credentials may be stored in clear text within the indexserver trace files of the control system. An attacker with the necessary authorizations on the control system could access these credentials, leading to unauthorized data access in both the captured and target systems.
Solution
The issue has been resolved in the following revisions. Update to these versions or later:
- SAP HANA 1 SP12: 122.15
- SAP HANA 2 SP01: 12.03
- SAP HANA 2 SP02: 23
As a workaround before updating, adjust the trace levels: set global.ini->trace->workloadreplaycmd on the control system side and wlreplayer.ini->trace->workloadreplayerservice on the replayer side to error. Alternatively, use the password reset feature in SAP HANA Cockpit (version 2.4.11 or later) to reset captured user passwords, ensuring that only chosen passwords appear in the trace files.
CVSS
Score 7.6 Vector: AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected components
- SAP HANA 1 SP12: 122.15 and before
- SAP HANA 2 SP01: 12.03 and before
- SAP HANA 2 SP02: 23 and before
Full note on SAP: SAP Support Launchpad note 2587369
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



