SAP Security Note
High priority
SAP security note 2658279, "[CVE-2018-2503] Wrong default authorizations in AS Java keystore service", is a program error note released on 11.12.2018. Below are the symptom and SAP recommended solution.
Description
Symptom
By default, the keystore service does not sufficiently restrict access to resources that should be protected. Some known impacts of insufficient access restrictions include:
- Read, modify, or delete sensitive information
Solution
Apply the corrective measures as per the ‘Validity’ and ‘Patch Level’ sections of this note.
CVSS
Score 7.4 Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
References
- Central note for SAP NetWeaver 7.31 SP24 Application Server Java
- NW AS JAVA applications fail to start after update
Full note on SAP: SAP Support Launchpad note 2658279
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
