SAP security note 2978768, “[CVE-2020-26834] Improper authentication in SAP HANA database”, is released on 08.12.2020. Below are the symptom and the SAP recommended solution.
Description
Symptom
The SAP HANA database does not correctly validate the user name when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a user whose name is identical to the truncated user name for whom the SAML bearer token was issued.
Solution
The issue is fixed with the following revisions:
- Revision 122.33 for SAP HANA 1.0 SPS 12
- Revision 48.03 for SAP HANA 2.0 SPS 04
- Revision 53 for SAP HANA 2.0 SPS 05
Update to these or later versions.
Workaround: Disable SAML authentication for affected users.
Reason and prerequisites
To exploit this vulnerability, an attacker must have access to a valid SAML bearer token and the SAP HANA database must be configured to accept this token. Furthermore, there must also be a valid user in the system whose user name is identical to the beginning of the user name in the SAML bearer token. These users must also be enabled for SAML authentication.
CVSS
Score 4.2
Full note on SAP: SAP Support Launchpad note 2978768
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
