SAP Security Note
Medium priority
SAP security note 2940823, "[CVE-2020-6297] Information Disclosure in SAP Data Intelligence", is a program error note released on August 11, 2020. Below are the symptom and SAP recommended solution.
Description
Symptom
During upgrade or installation, SAP Data Intelligence allows an attacker with access to a specific Kubernetes cluster to read highly sensitive data such as system passwords. This vulnerability enables the attacker to modify or delete data, impacting the availability of the affected cluster.
Solution
- Rotate credentials: change the credentials of the SAP Data Intelligence cluster admin used for the upgrade.
- Manage logs: truncate or remove pod logs on the Kubernetes nodes to prevent unauthorized access to sensitive information.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Full note on SAP: SAP Support Launchpad note 2940823
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



