SAP security note 2590705, "[CVE-2018-2451] Unsecure xs CLI Session Timeout Handling in SAP HANA Extended Application Services, advanced". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP has released Security Note 2590705 addressing a critical vulnerability identified as CVE-2018-2451. This vulnerability pertains to the unsecure handling of session timeouts in the xs CLI of SAP HANA Extended Application Services, advanced. An attacker exploiting this flaw could maintain access to Controller resources even after user authorizations have been revoked or the user account has been deactivated, potentially leading to unauthorized access and misuse of session tokens.
Solution
To mitigate this vulnerability, upgrade to SAP HANA Extended Application Services, advanced model version 1.0.87 or later. Applying this update ensures that session tokens are properly invalidated upon logout or when user authorizations are revoked.
Additionally, update your local xs CLI installations as outlined in the SAP HANA Administration Guide. This update enhances the logout functionality by ensuring that revoked session tokens are promptly invalidated, reducing the risk of unauthorized access. Be aware that the default token cache timeout is set to 30 minutes for performance reasons, but this can be adjusted in the xscontroller.ini configuration file if needed.
CVSS
Score 6.6 Vector: AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Full note on SAP: SAP Support Launchpad note 2590705
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
