SAP security note 2971163, “[CVE-2020-26816] Missing Encryption in SAP NetWeaver AS Java (Key Storage Service)”. Below are the symptom and the SAP recommended solution.
Description
Symptom
UPDATE 22nd December 2020: This note has been re-released with updated ‘Support Packages & Patches’ information. Patch level has been updated for the release J2EE ENGINE SERVERCORE 7.30 SP021.
The key material in the SAP NetWeaver AS Java Keystore service that is stored in the database as DER encoded format is not encrypted. This vulnerability allows an attacker with administrator access to decode the keys and obtain application data and client credentials of adjacent systems. This significantly impacts confidentiality, as the disclosed information could include client credentials of other systems.
Solution
- Update your AS Java to a release or Support Package where the issue is fixed.
- Refer to the Validity and SP Patches sections of this note for detailed information and available patches.
- The Key Storage data will be encrypted on the next AS Java startup.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
References
- Importing AS Java Core patches for NetWeaver 7.1+
- Central note for SAP NetWeaver 7.31 SP28 Application Server Java
Full note on SAP: SAP Support Launchpad note 2971163
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




