Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0379 Missing Authentication Check in AS2 Adapter of B2B Add-On for SAP NetWeaver Process Integration, SAP security note 2826015

SAP Note 2826015

SAP security note 2826015, "[CVE-2019-0379] Missing Authentication Check in AS2 Adapter of B2B Add-On for SAP NetWeaver Process Integration". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

AS2 Adapter of B2B Add-On for SAP NetWeaver Process Integration does not perform properly authentication checks for functionalities that require user identity.

Some well-known impacts of Missing Authentication check are:

  • Read, modify, or delete sensitive information
  • Access administrative or other privileged functionalities

Solution

Apply the latest patch version for the component indicated in the "Support Packages & Patches" section of this SAP Note.

To eliminate this risk while your system is not yet updated, do the following: make sure the property named default.security.provider for the application named com.sap.aii.adapter.as2.app is set to its default value IAIK.

Reason and prerequisites

AS2 Adapter does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC).

CVSS

Score 9.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

Affected components

  • PIB2BAS2 from version 1.0 to 1.0
  • PIB2BAS2 from version 2.0 to 2.0

Full note on SAP: SAP Support Launchpad note 2826015

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More