SAP Security Note
High priority
SAP security note 2748699, "[CVE-2019-0291] Information Disclosure in Solution Manager 7.2 / CA Introscope Enterprise Manager", is a program error note released on 11.06.2019. Below are the symptom and the SAP recommended solution.
Description
Symptom
Under certain conditions, Solution Manager 7.2 allows an attacker to access information which would otherwise be restricted.
Some well-known impacts of Information Disclosure include:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
To secure the credentials file, perform the following steps:
- Deploy the LM-SERVICE Software Component, mentioned in the "Support Packages & Patches" section.
- Apply a new patch to the CA Introscope Enterprise Manager: Since the credentials file must be readable by CA Introscope Enterprise Manager, a new patch (Management Module [MM] package) must be applied. Details about MM can be found in SAP Note 1579474. Depending on the EM version, apply the corresponding SAP note patch: Note 2534316 Introscope 10.5 Release Notes, Note 2285189 Introscope 10.1 Release Notes.
- Change the password of the user SM_EXTERN_WS (or the user specified during configuration): Navigate to “Cross Scenario Configuration” – “Mandatory Configuration” – “System Preparation” – “Maintain Technical Users.”
- Generate the credentials file in a protected manner: In Solution Manager, run “Cross Scenario Configuration” – “Mandatory Configuration” – “Basic Configuration” – “Configure Basic Functions.” Execute the task “Push DPC Configuration to CA Introscope” to generate the credentials file securely. Verify the file content to ensure it includes the line: $internal/mode=encrypted
Reason and prerequisites
For the Solution Manager capability Monitoring and Alerting Infrastructure (MAI), the CA Introscope Enterprise Manager (EM) offers the service Introscope Push (see SAP Note 1751225) to actively push monitoring metrics from EM to Solution Manager. Introscope Push calls a Web Service of Solution Manager that requires authentication.
The username and password for the Introscope Push service are stored in a file referenced by the property dpcpush.credentials.file in the file <EM_install_dir>/sap/<SolMan_SID>.e2emai.properties.
The credentials in the referenced file are insufficiently protected against attackers.
The standard user SM_EXTERN_WS, used for Introscope Push, is by default a system user (no dialog user) with limited permissions and an automatically generated password valid only for this user.
You may have configured your own user in Solution Manager during the configuration step: “Cross Scenario Configuration” – “Mandatory Configuration” – “System Preparation” – “Maintain Technical Users” with Use Case ID as SM_EXTERN_WS.
CVSS
Score 7.1 Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2748699
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



