SAP security note 2838835, “[CVE-2020-6190] Information Disclosure in SAP NetWeaver AS Java (Heap Dump Application)”. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP NetWeaver AS Java Heap Dump Application allows an attacker to exploit certain misconfigured application endpoints to read sensitive data without authentication. These endpoints are normally exposed over the network and successful exploitation can lead to exposure of data like Host Name, server Node, and the installation path that could help the attacker collect information about the NetWeaver implementation.
Solution
Update your AS Java to a Support Package (SP) or release where the issue is fixed. See the Support Package Patch Level section for details and available patches.
The solution disables the Heap Dump Application so that it is not started and not accessible anymore. You may use some offline tool for Heap Dump Analysis.
Reason and prerequisites
Any information can be seen only if the system had heap dump analysis performed on it.
CVSS
Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2838835
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
