Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6307 Missing Authorization Check in Automated Note Search Tool (SAP_BASIS), SAP security note 2863397

SAP Note 2863397

SAP security note 2863397, “[CVE-2020-6307] Missing Authorization Check in Automated Note Search Tool (SAP_BASIS)”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

  • Issue: ANST (Automated Note Search Tool) does not perform sufficient authorization checks during the ‘Trace On/Off’ functionality. This vulnerability allows unauthorized users to read sensitive information.
  • Impact: Potential exposure of sensitive data, increasing the risk of Remote Command Execution (RCE) attacks and compromising the confidentiality of SAP Systems.

Solution

  • Implement Corrections: Apply the correction instructions provided in this SAP Note.
  • Update Support Packages: Alternatively, update to the corresponding support package that includes these corrections.
  • Post-Implementation: After applying this note, users will only be able to view their own traces. To share traces with others, use the download option and share the traces through approved channels.

Reason and prerequisites

SAP Note 2253694 disables the necessary authorization checks, leading to the vulnerability.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References

Affected components

  • SAP_BASIS Versions: 700 to 754, including DEV

Full note on SAP: SAP Support Launchpad note 2863397

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More