SAP Security Note
HotNews
SAP security note 2985866, "[Multiple CVE IDs] Missing Authentication Check in SAP Solution Manager (JAVA stack)", is a program error note released on 10.11.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
Some authentication checks are missing in SAP Solution Manager (software component LM-SERVICE). An unauthenticated attacker is able to compromise the system, affecting the integrity and availability of the service. The affected services are:
- SVG Converter Service – CVE-2020-26821
- Outside Discovery Configuration Service – CVE-2020-26822
- Upgrade Diagnostics Agent Connection Service – CVE-2020-26823
- Upgrade Legacy Ports Service – CVE-2020-26824
Solution
The fix enables user authentication. Apply the patches listed in the Support Package Patches section below.
Reason and prerequisites
This issue is relevant for all customers using SAP Solution Manager 7.2 on Support Package SP11 and lower.
CVSS
Score 10.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
References
- SAP Note 2978778 – LM-SERVICE 7.20 SP 11 Patch 4
- SAP Note 2898961 – LM-SERVICE 7.20 SP 8 Patch 16
- SAP Note 2898904 – LM-SERVICE 7.20 SP 9 Patch 8
Full note on SAP: SAP Support Launchpad note 2985866
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
