Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0306 Information Disclosure in SAP HANA Extended Application Services (advanced model), SAP security note 2771128

SAP Note 2771128

SAP security note 2771128, "[CVE-2019-0306] Information Disclosure in SAP HANA Extended Application Services (advanced model)", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, the SAP HANA XS Advanced server allows platform users to access more information than required.

Some well-known impacts of Information Disclosure are:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The vulnerability has been fixed with SAP HANA Extended Application Services, advanced model version 1.0.115. Apply this or later versions. After patching the system, user IDs and names of platform users will only be visible to administrative users or users of the same space or organization.

The patch might cause malfunction of some user management commands in former versions of the XS client and XSA Cockpit. Hence, updating XSA Cockpit to at least version 1.1.12 and the XS client to at least version 1.0.114 might be required. Please find details in the release notes of XS Advanced version 1.0.115.

Reason and prerequisites

Authenticated, low-privileged XS Advanced platform users such as SpaceAuditors can execute requests to obtain a complete list of SAP HANA user IDs and names.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected components

  • SAP_EXTENDED_APP_SERVICES: version 1
  • XS RUNTIME: version 1
  • XSA COCKPIT: version 1

Full note on SAP: SAP Support Launchpad note 2771128

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More