SAP security note 2738791, "[CVE-2019-0318] Information disclosure in SAP NetWeaver AS Java (Startup Framework)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, SAP java startup / jstart allows an attacker to access information which would otherwise be restricted.
Some well-known impacts of Information Disclosure are:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
The output of security-relevant information was removed. Please implement the patch level mentioned (or higher) in this SAP Note.
Reason and prerequisites
By using a higher trace level, the jstart program might expose credential information to trace files. For versions 7.21, 7.22, 7.45, 7.49, and 7.53, the issue may occur from trace level 3 onward.
CVSS
Score 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected components
- KRNL32NUC 7.21, 7.21EXT
- KRNL32UC 7.21, 7.21EXT
- KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49
- KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53
- KERNEL 7.21 to 7.22+, 7.45 to 7.45+, 7.49 to 7.49+, 7.53 to 7.53+
Full note on SAP: SAP Support Launchpad note 2738791
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
