SAP security note 2877968, "[CVE-2020-6192] Missing Input Validation in SAP Landscape Management". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker with admin privileges could execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management due to missing input validation.
Solution
Install SAP Landscape Management 3.0 SP13 Patch 3.
Install the SAP Adaptive Extensions Patch 52 on all managed hosts where SAP Adaptive Extensions have been installed before (e.g., SAP HANA hosts, appliance provisioning).
Execute a mass validation on all hosts of your landscape for validator RuntimeInternalOperationValidator to activate the fixes immediately. If not executed manually, fixes will be enabled with the next automatic execution of the validation (24h by default). For more information, see Validating Hosts.
Ensure you install SAP Landscape Management 3.0 SP13 Patch 3 before installing SAP Adaptive Extensions Patch 52.
If the operations.d directory of your managed hosts is mounted, update *.conf files from SAP Adaptive Extensions Patch 52 as per SAP Note 1550099.
CVSS
Score 7.2 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References
- SAP Landscape Management 3.0 SP13 Patch03
- SAP Adaptive Extension: Fixes for Patch 01 to Patch 55
- Additional Host Agent Operations
Affected components
- SAP Landscape Management
- SAP Host Agent
Full note on SAP: SAP Support Launchpad note 2877968
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
