Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Connect to Oracle database, SAP security note 1623922

SAP Note 1623922
SAP Security Note
High priority

SAP security note 1623922, "Connect to Oracle Database", is a consulting note released on November 7, 2011. Below are the symptom, SAP recommended solution and references.

ComponentBasis Components > Database Interface, Database Platforms > Oracle > Database Interface / DBMS
CategoryConsulting
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onNovember 7, 2011

Description

Symptom

A vulnerability has been identified in the SAP connection to the Oracle database using the OPS$ method. This vulnerability allows a malicious user to log on to the database as an OPS$ user without entering a password unless appropriate measures are taken.

The connection to the Oracle database using the OPS$ method contains a vulnerability that permits unauthorized access without a password.

Solution

Connection methods overview:

  • Versions 4.6D, 6.40, 7.00 to 7.11: Use the OPS$ method.
  • Version 7.20 (patch 100) and higher with Oracle 10/11: OPS$ method or Secure Store (recommended).
  • Oracle 12 and higher: Secure Store method recommended.

Reason and prerequisites

Up to SAP kernel version 7.11 and Oracle up to version 11.2, the SAP database user’s password is stored encrypted in a table accessible only by the OPS$ user. Without secure measures, this can be exploited.

References

Full note on SAP: SAP Support Launchpad note 1623922

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More