SAP Security Note
HotNews
SAP security note 627649, "Credit card data is stored in the log file", is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Credit card information relevant for security may be written to the J2EE engine log file isa.log located in the WEB-INF/log directory.
This data can be misused by authorized or unauthorized persons who have access to the log files, posing a significant security hazard. This issue affects both ISA for CRM and ISA for R/3.
Solution
The correction ensures that no credit card information is written to the isa.log files regardless of the log level setting.
- Included in Release 3.0 as of Support Package 16
- Included in Release 3.1 as of Support Package 06
- Included in Release 4.0 as of Support Package 02
Corrections are available in:
- Support Package 12 for CRM 3.0
- Support Package 13 for CRM 3.0 on the Service Marketplace
- Support Package 14 for CRM 3.0 as of calendar week 14/2004
For other support packages, request a correction as an advance correction by creating an SAPNet R/3 Frontend message referencing this note.
Reason and prerequisites
The prerequisite for credit card data being written to the log files is that the log level for com.sapmarkets.isa is set to DEBUG. The DEBUG setting is intended only for testing purposes and should never be used in production systems except for problem analysis. The standard log level for productive operations should be ERROR, which only generates entries when errors occur. For more information on the different log levels and their configuration, refer to the ISA 3.1 CRM E-Selling: Business Scenario Configuration Guide available on the Service Marketplace. This document also applies to ISA 3.0 and ISA 4.0.
References
This note refers to
Referenced by
Affected components
- BBPCRM: 300, 310, 400
CVSS
Score 0
Full note on SAP: SAP Support Launchpad note 627649
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
