SAP security note 2742027, "[CVE-2019-0261] Missing authentication check in SAP HANA Extended Application Services, advanced model", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users.
Some well-known impacts of faulty authentication checks are:
- Unauthorized access (read, modify, or delete) to sensitive information
- Unauthorized access to administrative or other privileged functionalities
Solution
It is recommended to upgrade XS advanced to version 1.0.100 or higher. An update of the underlying SAP HANA system is not required.
In urgent cases or when updating the XS advanced system is not possible on short notice, the following workaround can be applied.
Reason and prerequisites
Authentication check for XS advanced users based on SAP HANA user management does not work as expected.
Affected are XS advanced runtime versions 1.0.97 to 1.0.99 running on SAP HANA 1 or SAP HANA 2 SPS0. You may check both versions by executing xs version with the xs command line client (xs CLI).
CVSS
Score 9.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Affected components
- SAP_EXTENDED_APP_SERVICES: 1
Full note on SAP: SAP Support Launchpad note 2742027
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
