Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6297 Information Disclosure in SAP Data Intelligence, SAP security note 2940823

SAP Note 2940823
SAP Security Note
Medium priority

SAP security note 2940823, "[CVE-2020-6297] Information Disclosure in SAP Data Intelligence", is a program error note released on August 11, 2020. Below are the symptom and SAP recommended solution.

ComponentCA-DI-ONP
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onAugust 11, 2020
LanguageEnglish

Description

Symptom

During upgrade or installation, SAP Data Intelligence allows an attacker with access to a specific Kubernetes cluster to read highly sensitive data such as system passwords. This vulnerability enables the attacker to modify or delete data, impacting the availability of the affected cluster.

Solution

  • Rotate credentials: change the credentials of the SAP Data Intelligence cluster admin used for the upgrade.
  • Manage logs: truncate or remove pod logs on the Kubernetes nodes to prevent unauthorized access to sensitive information.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Full note on SAP: SAP Support Launchpad note 2940823

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More