Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6192 Missing Input Validation in SAP Landscape Management, SAP security note 2877968

SAP Note 2877968

SAP security note 2877968, "[CVE-2020-6192] Missing Input Validation in SAP Landscape Management". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker with admin privileges could execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management due to missing input validation.

Solution

Install SAP Landscape Management 3.0 SP13 Patch 3.

Install the SAP Adaptive Extensions Patch 52 on all managed hosts where SAP Adaptive Extensions have been installed before (e.g., SAP HANA hosts, appliance provisioning).

Execute a mass validation on all hosts of your landscape for validator RuntimeInternalOperationValidator to activate the fixes immediately. If not executed manually, fixes will be enabled with the next automatic execution of the validation (24h by default). For more information, see Validating Hosts.

Ensure you install SAP Landscape Management 3.0 SP13 Patch 3 before installing SAP Adaptive Extensions Patch 52.

If the operations.d directory of your managed hosts is mounted, update *.conf files from SAP Adaptive Extensions Patch 52 as per SAP Note 1550099.

CVSS

Score 7.2 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References

Affected components

  • SAP Landscape Management
  • SAP Host Agent

Full note on SAP: SAP Support Launchpad note 2877968

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More