Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Basic settings for reg_info and sec_info, SAP security note 1408081

SAP Note 1408081
SAP Security Note

SAP security note 1408081, "Basic settings for reg_info and sec_info", is a note released on May 14, 2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-CST-GW (Basis Components > Client/Server Technology > Gateway/CPIC)
TypeSAP Security Note
Version22
Released onMay 14, 2019

Description

Symptom

Since the SAP Gateway is an interface of the application server to external items (other SAP systems, external programs, etc.), it is crucial to fulfill security criteria to protect the entire SAP system. The security of the SAP Gateway is managed via the reg_info and sec_info files, defined by the instance profile parameters gw/reg_info and gw/sec_info.

Solution

The reg_info and sec_info files control the registration and execution of external programs. Proper configuration enhances system security while maintaining minimal maintenance effort. The keyword "local" is available in SAP Kernel Releases 46D and 640; the keyword "internal" is available starting from SAP Kernel Release 720.

  • Place reg_info and sec_info in a shared directory for maintainability.
  • Ensure profile parameter gw/reg_no_conn_info is active to prevent bypassing sec_info and reg_info.
  • Use encryption for communications outside the DMZ using SAProuter.

CVSS

Score 4.8 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

References

Affected components

  • SAP_BASIS: 46D, 640, 700 to 702, 710 to 730, 731, 740+

Full note on SAP: SAP Support Launchpad note 1408081

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More