Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0318 Information disclosure in SAP NetWeaver AS Java (Startup Framework), SAP security note 2738791

SAP Note 2738791

SAP security note 2738791, "[CVE-2019-0318] Information disclosure in SAP NetWeaver AS Java (Startup Framework)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, SAP java startup / jstart allows an attacker to access information which would otherwise be restricted.

Some well-known impacts of Information Disclosure are:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The output of security-relevant information was removed. Please implement the patch level mentioned (or higher) in this SAP Note.

Reason and prerequisites

By using a higher trace level, the jstart program might expose credential information to trace files. For versions 7.21, 7.22, 7.45, 7.49, and 7.53, the issue may occur from trace level 3 onward.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected components

  • KRNL32NUC 7.21, 7.21EXT
  • KRNL32UC 7.21, 7.21EXT
  • KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49
  • KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53
  • KERNEL 7.21 to 7.22+, 7.45 to 7.45+, 7.49 to 7.49+, 7.53 to 7.53+

Full note on SAP: SAP Support Launchpad note 2738791

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More