Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Multiple CVE IDs Missing Authentication Check in SAP Solution Manager (JAVA stack), SAP security note 2985866

SAP Note 2985866
SAP Security Note
HotNews

SAP security note 2985866, "[Multiple CVE IDs] Missing Authentication Check in SAP Solution Manager (JAVA stack)", is a program error note released on 10.11.2020. Below are the symptom and SAP recommended solution.

ComponentService > SAP Solution Manager > Monitoring & Alerting > End User Experience Monitoring
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on10.11.2020
LanguageEnglish

Description

Symptom

Some authentication checks are missing in SAP Solution Manager (software component LM-SERVICE). An unauthenticated attacker is able to compromise the system, affecting the integrity and availability of the service. The affected services are:

  • SVG Converter Service – CVE-2020-26821
  • Outside Discovery Configuration Service – CVE-2020-26822
  • Upgrade Diagnostics Agent Connection Service – CVE-2020-26823
  • Upgrade Legacy Ports Service – CVE-2020-26824

Solution

The fix enables user authentication. Apply the patches listed in the Support Package Patches section below.

Reason and prerequisites

This issue is relevant for all customers using SAP Solution Manager 7.2 on Support Package SP11 and lower.

CVSS

Score 10.0 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2985866

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More