SAP security note 2826015, "[CVE-2019-0379] Missing Authentication Check in AS2 Adapter of B2B Add-On for SAP NetWeaver Process Integration". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
AS2 Adapter of B2B Add-On for SAP NetWeaver Process Integration does not perform properly authentication checks for functionalities that require user identity.
Some well-known impacts of Missing Authentication check are:
- Read, modify, or delete sensitive information
- Access administrative or other privileged functionalities
Solution
Apply the latest patch version for the component indicated in the "Support Packages & Patches" section of this SAP Note.
To eliminate this risk while your system is not yet updated, do the following: make sure the property named default.security.provider for the application named com.sap.aii.adapter.as2.app is set to its default value IAIK.
Reason and prerequisites
AS2 Adapter does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC).
CVSS
Score 9.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Affected components
- PIB2BAS2 from version 1.0 to 1.0
- PIB2BAS2 from version 2.0 to 2.0
Full note on SAP: SAP Support Launchpad note 2826015
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
