Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6198 Missing Authentication check in SAP Solution Manager (Diagnostics Agent), SAP security note 2845377

SAP Note 2845377

SAP security note 2845377, “[CVE-2020-6198] Missing Authentication check in SAP Solution Manager (Diagnostics Agent)”. Below are the symptom and SAP recommended solution.

Description

Symptom

The Diagnostics Agent allows P4 connections from unauthenticated sources to an insecure server port. This vulnerability enables an attacker to control all remote functions on the Agent, resulting in:

  • Access to sensitive data stored in the configuration.
  • Execution of commands with the permissions of the <SID>adm user, including modification of sensitive data.
  • Shutdown of the Agent, disabling monitoring and causing it to be unavailable.

An attacker exploiting this vulnerability can fully compromise the Diagnostics Agent, leading to unauthorized access, data manipulation, and service disruption.

Solution

To mitigate this vulnerability, update to the latest LM-Service version. This update will close the insecure server port, removing the ability to establish unauthorized connections.

Reason and prerequisites

The Diagnostics Agent opens an insecure server port where authentication controls can be bypassed.

CVSS

Score 9.8 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Full note on SAP: SAP Support Launchpad note 2845377

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More