Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Credentials are stored in memory by SAP MDM GDS 2.1, SAP security note 1605531

SAP Note 1605531

SAP security note 1605531, “Credentials are stored in memory by SAP MDM GDS 2.1”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

  • Credentials of logged-in users are kept in memory for the duration of their session.
  • When user properties are read from MDM, passwords are kept in memory until the application is stopped.
  • A malicious user with an operating system account on the GDS server and appropriate rights may steal credentials from the memory.

Solution

Implement the relevant patch for SAP MDM GDS 2.1 to address this vulnerability.

Reason and prerequisites

The GDS application unnecessarily retains user credentials in plain text in memory for an extended period, increasing the risk of credential theft by malicious users with access to the server’s operating system.

References

Affected components

  • GDSCORE: 2.1
  • GDSTOOLS: 2.1
  • GDSUI: 2.1

Full note on SAP: SAP Support Launchpad note 1605531

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More