Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2440 Sensitive Information Exposure in SAP Dynamic Authorization Management by NextLabs, SAP security note 2664767

SAP Note 2664767

SAP security note 2664767, "CVE-2018-2440 – Sensitive Information Exposure in SAP Dynamic Authorization Management". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, SAP Dynamic Authorization Management (DAM) exposes sensitive information in the application logs.

Impacts of information disclosure include:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The feature of logging sensitive details has been removed and a new version SAP Jco EntitlementManager 7.6.2 has been generated.

CVSS

Score 4.4 Vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

References

  • CVE-2018-2440

Affected components

  • NEXTLABSJAVAPOLICYCONTROLLE: Versions 7.7.0.0 and 8.5

Full note on SAP: SAP Support Launchpad note 2664767

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More