SAP security note 2903743, "Information Disclosure in SAP Landscape Management", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A disclosure vulnerability exists in the enterprise edition or standard edition of SAP Landscape Management that allows an authenticated user with high privileges to obtain privileged access to other systems, making those systems vulnerable to information disclosure and modification.
The information disclosed includes credentials. To fix the problem, follow these steps:
- Implement SAP Landscape Management 3.0 SP14 Patch02.
- Remove all SAP NetWeaver Developer Traces and archives of traces with severity Path or higher.
- Change the affected credentials because the logs could have already been read.
Solution
Implement SAP Landscape Management 3.0 SP14 Patch02.
Reason and prerequisites
- SAP Landscape Management, standard edition or enterprise edition is used.
- The SAP NetWeaver Developer Traces severity is set to Path or higher.
- One or more of the following activities: automatic monitoring job triggered for SAP HANA entities; execution of SAP HANA monitoring by an operation, custom process, operation template, or schedule; execution of provisioning processes that receive secure parameters or passwords.
- Prerequisites 2 and 3 occur within the retention period of persisted SAP NetWeaver Developer Traces.
CVSS
Score 8.7 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
References
Affected components
- Virtualization / Cloud Management > Landscape Virtualization Management (BC-VCM-LVM)
- VCM LVM 3.0
Full note on SAP: SAP Support Launchpad note 2903743
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
