Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2402 Potential information disclosure in SAP HANA capture & replay trace file, SAP security note 2587369

SAP Note 2587369

SAP security note 2587369, "[CVE-2018-2402] Potential information disclosure in SAP HANA capture & replay trace file", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

In systems utilizing the optional capture & replay functionality of SAP HANA, there is a vulnerability where user credentials may be stored in clear text within the indexserver trace files of the control system. An attacker with the necessary authorizations on the control system could access these credentials, leading to unauthorized data access in both the captured and target systems.

Solution

The issue has been resolved in the following revisions. Update to these versions or later:

  • SAP HANA 1 SP12: 122.15
  • SAP HANA 2 SP01: 12.03
  • SAP HANA 2 SP02: 23

As a workaround before updating, adjust the trace levels: set global.ini->trace->workloadreplaycmd on the control system side and wlreplayer.ini->trace->workloadreplayerservice on the replayer side to error. Alternatively, use the password reset feature in SAP HANA Cockpit (version 2.4.11 or later) to reset captured user passwords, ensuring that only chosen passwords appear in the trace files.

CVSS

Score 7.6 Vector: AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Affected components

  • SAP HANA 1 SP12: 122.15 and before
  • SAP HANA 2 SP01: 12.03 and before
  • SAP HANA 2 SP02: 23 and before

Full note on SAP: SAP Support Launchpad note 2587369

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More