Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26834 Improper authentication in SAP HANA database, SAP security note 2978768

SAP Note 2978768

SAP security note 2978768, “[CVE-2020-26834] Improper authentication in SAP HANA database”, is released on 08.12.2020. Below are the symptom and the SAP recommended solution.

ComponentSAP HANA Security & User Management (HAN-DB-SEC)
StatusReleased for Customer
Released on08.12.2020

Description

Symptom

The SAP HANA database does not correctly validate the user name when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a user whose name is identical to the truncated user name for whom the SAML bearer token was issued.

Solution

The issue is fixed with the following revisions:

  • Revision 122.33 for SAP HANA 1.0 SPS 12
  • Revision 48.03 for SAP HANA 2.0 SPS 04
  • Revision 53 for SAP HANA 2.0 SPS 05

Update to these or later versions.

Workaround: Disable SAML authentication for affected users.

Reason and prerequisites

To exploit this vulnerability, an attacker must have access to a valid SAML bearer token and the SAP HANA database must be configured to accept this token. Furthermore, there must also be a valid user in the system whose user name is identical to the beginning of the user name in the SAML bearer token. These users must also be enabled for SAML authentication.

CVSS

Score 4.2

Full note on SAP: SAP Support Launchpad note 2978768

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More