SAP security note 2836445, “[CVE-2020-6183] Unprivileged Access to Technical Data Using SAPOSCOL of SAP Host Agent”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The SAP Oscollector allows an unauthenticated attacker to query the background service that would otherwise be restricted to authorized users. The SAP Oscollector, typically exposed only internally, can be attacked from within the network. Exploiting this vulnerability allows the attacker to obtain statistics such as CPU, RAM, directory size, and more. Additionally, the attacker may be able to stop the collection process, affecting the service’s availability. If the attacker lacks access to the SAPOSCOL binary, they could copy it to their home folder and perform the attack.
Solution
This correction ensures that the shared memory is created with read/write permissions only for the root user or users in the “sapsys” group, restricting access to the SAPOSCOL main process to those users.
- For Linux: The solution is enabled by default. If there are negative impacts, you can disable it by adding the profile parameter
ipc/shm_permission_1002 = 0777to the HostAgent profile/usr/sap/hostctrl/exe/host_profile. - For Unix: The solution is disabled by default to avoid impacting other consumers. Enable it by adding the profile parameter
ipc/shm_permission_1002 = 0770to the HostAgent profile/usr/sap/hostctrl/exe/host_profileand as the profile parameter of work processes.
The functionality is available with the version of SAP Host Agent mentioned in this SAP Security Note.
Reason and prerequisites
A malicious user can run SAPOSCOL and read data stored in the SAPOSCOL process. The SAPOSCOL process on Linux and Unix-like operating systems runs under the root user and creates shared memory to inform other processes about system information. The shared memory is public with read/write permissions for anyone.
If an unprivileged user downloads the SAPOSCOL binary from official SAP repositories or creates their own program, they can read or write to the shared memory by sending requests to the main SAPOSCOL process and receiving responses containing data with root privileges (e.g., directory sizes).
CVSS
Score 5.3 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
This note refers to
Affected components
- SAP Host Agent 7.21 to 7.21
Full note on SAP: SAP Support Launchpad note 2836445
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



