Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2451 Unsecure xs CLI session timeout handling in SAP HANA Extended Application Services, advanced, SAP security note 2590705

SAP Note 2590705

SAP security note 2590705, "[CVE-2018-2451] Unsecure xs CLI Session Timeout Handling in SAP HANA Extended Application Services, advanced". Below are the symptom and SAP recommended solution.

ComponentBC-XS-SEC (Basis Components > HANA XS Advanced > UAA and Security for HANA XSA engine)

Description

Symptom

SAP has released Security Note 2590705 addressing a critical vulnerability identified as CVE-2018-2451. This vulnerability pertains to the unsecure handling of session timeouts in the xs CLI of SAP HANA Extended Application Services, advanced. An attacker exploiting this flaw could maintain access to Controller resources even after user authorizations have been revoked or the user account has been deactivated, potentially leading to unauthorized access and misuse of session tokens.

Solution

To mitigate this vulnerability, upgrade to SAP HANA Extended Application Services, advanced model version 1.0.87 or later. Applying this update ensures that session tokens are properly invalidated upon logout or when user authorizations are revoked.

Additionally, update your local xs CLI installations as outlined in the SAP HANA Administration Guide. This update enhances the logout functionality by ensuring that revoked session tokens are promptly invalidated, reducing the risk of unauthorized access. Be aware that the default token cache timeout is set to 30 minutes for performance reasons, but this can be adjusted in the xscontroller.ini configuration file if needed.

CVSS

Score 6.6 Vector: AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Full note on SAP: SAP Support Launchpad note 2590705

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More