SAP security note 2817491, "[CVE-2019-0363] Multiple security vulnerabilities in SAP HANA Extended Application Services (Advanced Model)". Below are the symptom and SAP recommended solution.
Description
Symptom
This note addresses multiple vulnerabilities in SAP HANA Extended Application Services (Advanced Model):
Denial of Service (DoS). Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model) to overload the server or retrieve information about internal network ports. CVE-2019-0363. CVSS Score: 7.7, Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H. Impacts: long response delays and service interruptions, degrading the service quality experienced by legitimate users; direct impact on availability.
Internal Port Scanning. Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model) to enumerate open ports. CVE-2019-0364. CVSS Score: 5.0, Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N.
Solution
The vulnerability has been fixed with SAP HANA Extended Application Services (Advanced model) version 1.0.118. Implement the Support Packages and Patches referenced by this SAP Note 2817491.
Reason and prerequisites
Port scanning on the HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model) reveals some of the open ports, which could be exploited to cause a denial of service attack. This attack affects the entire XS advanced system, including the SAP HANA database. Any authenticated user can exploit this vulnerability without needing additional authorizations.
CVSS
Score 7.7 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Full note on SAP: SAP Support Launchpad note 2817491
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
