SAP Security Note
Low priority
SAP security note 2927373, “Information Disclosure in SAP NetWeaver”, is a program error note released on 13.07.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions, SAP NetWeaver (ABAP Server) and ABAP Platform allow an attacker with admin privileges to access certain files which should otherwise be restricted.
Impacts of Information Disclosure:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
Apply the correction provided in this SAP Note to implement consistent protection for search and download functionalities, similar to direct navigation.
- ABAP 7.31 to ABAP 7.53: Introduced a blacklist and implemented consistent protection.
- ABAP 7.54: Continued implementation of consistent protection.
Action Required: Please implement the Support Package mentioned in this SAP Note or follow the respective correction instructions.
Reason and prerequisites
Transaction AL11 enables administrators to access the file system conveniently from within the SAP system. Using the search functionality introduced with ABAP 7.31, some directories or files that are secured from access via transaction AL11 may be displayed for selection. Additionally, the file download feature can be used to download files that should not be accessible.
CVSS
Score 2.7 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2927373
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
