SAP Security Note
SAP security note 1408081, "Basic settings for reg_info and sec_info", is a note released on May 14, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Since the SAP Gateway is an interface of the application server to external items (other SAP systems, external programs, etc.), it is crucial to fulfill security criteria to protect the entire SAP system. The security of the SAP Gateway is managed via the reg_info and sec_info files, defined by the instance profile parameters gw/reg_info and gw/sec_info.
Solution
The reg_info and sec_info files control the registration and execution of external programs. Proper configuration enhances system security while maintaining minimal maintenance effort. The keyword "local" is available in SAP Kernel Releases 46D and 640; the keyword "internal" is available starting from SAP Kernel Release 720.
- Place
reg_infoandsec_infoin a shared directory for maintainability. - Ensure profile parameter
gw/reg_no_conn_infois active to prevent bypassingsec_infoandreg_info. - Use encryption for communications outside the DMZ using SAProuter.
CVSS
Score 4.8 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
References
This note refers to
Affected components
- SAP_BASIS: 46D, 640, 700 to 702, 710 to 730, 731, 740+
Full note on SAP: SAP Support Launchpad note 1408081
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
