Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0261 Missing authentication check in SAP HANA Extended Application Services, advanced model, SAP security note 2742027

SAP Note 2742027

SAP security note 2742027, "[CVE-2019-0261] Missing authentication check in SAP HANA Extended Application Services, advanced model", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users.

Some well-known impacts of faulty authentication checks are:

  • Unauthorized access (read, modify, or delete) to sensitive information
  • Unauthorized access to administrative or other privileged functionalities

Solution

It is recommended to upgrade XS advanced to version 1.0.100 or higher. An update of the underlying SAP HANA system is not required.

In urgent cases or when updating the XS advanced system is not possible on short notice, the following workaround can be applied.

Reason and prerequisites

Authentication check for XS advanced users based on SAP HANA user management does not work as expected.

Affected are XS advanced runtime versions 1.0.97 to 1.0.99 running on SAP HANA 1 or SAP HANA 2 SPS0. You may check both versions by executing xs version with the xs command line client (xs CLI).

CVSS

Score 9.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Affected components

  • SAP_EXTENDED_APP_SERVICES: 1

Full note on SAP: SAP Support Launchpad note 2742027

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More