SAP Security Note
HotNews
SAP security note 2727624, "[CVE-2019-0249] Information Disclosure in SAP Landscape Management", is a program error note released on 08.01.2019. Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions, SAP Landscape Management allows an attacker to access information which would otherwise be restricted. This allows attackers to gather user credentials for further exploits and attacks.
Solution
- Implement the referenced SAP Landscape Management Patch.
- Perform the manual correction instructions described in this SAP Note.
Reason and prerequisites
Execution of "Install Application Server" on a system with a single-tenant or multi-tenant SAP HANA database.
CVSS
Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Full note on SAP: SAP Support Launchpad note 2727624
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
