Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26816 Missing Encryption in SAP NetWeaver AS Java (Key Storage Service), SAP security note 2971163

SAP Note 2971163

SAP security note 2971163, “[CVE-2020-26816] Missing Encryption in SAP NetWeaver AS Java (Key Storage Service)”. Below are the symptom and the SAP recommended solution.

Description

Symptom

UPDATE 22nd December 2020: This note has been re-released with updated ‘Support Packages & Patches’ information. Patch level has been updated for the release J2EE ENGINE SERVERCORE 7.30 SP021.

The key material in the SAP NetWeaver AS Java Keystore service that is stored in the database as DER encoded format is not encrypted. This vulnerability allows an attacker with administrator access to decode the keys and obtain application data and client credentials of adjacent systems. This significantly impacts confidentiality, as the disclosed information could include client credentials of other systems.

Solution

  • Update your AS Java to a release or Support Package where the issue is fixed.
  • Refer to the Validity and SP Patches sections of this note for detailed information and available patches.
  • The Key Storage data will be encrypted on the next AS Java startup.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2971163

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More