SAP security note 2845377, “[CVE-2020-6198] Missing Authentication check in SAP Solution Manager (Diagnostics Agent)”. Below are the symptom and SAP recommended solution.
Description
Symptom
The Diagnostics Agent allows P4 connections from unauthenticated sources to an insecure server port. This vulnerability enables an attacker to control all remote functions on the Agent, resulting in:
- Access to sensitive data stored in the configuration.
- Execution of commands with the permissions of the <SID>adm user, including modification of sensitive data.
- Shutdown of the Agent, disabling monitoring and causing it to be unavailable.
An attacker exploiting this vulnerability can fully compromise the Diagnostics Agent, leading to unauthorized access, data manipulation, and service disruption.
Solution
To mitigate this vulnerability, update to the latest LM-Service version. This update will close the insecure server port, removing the ability to establish unauthorized connections.
Reason and prerequisites
The Diagnostics Agent opens an insecure server port where authentication controls can be bypassed.
CVSS
Score 9.8 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Full note on SAP: SAP Support Launchpad note 2845377
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
