SAP security note 2863397, “[CVE-2020-6307] Missing Authorization Check in Automated Note Search Tool (SAP_BASIS)”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
- Issue: ANST (Automated Note Search Tool) does not perform sufficient authorization checks during the ‘Trace On/Off’ functionality. This vulnerability allows unauthorized users to read sensitive information.
- Impact: Potential exposure of sensitive data, increasing the risk of Remote Command Execution (RCE) attacks and compromising the confidentiality of SAP Systems.
Solution
- Implement Corrections: Apply the correction instructions provided in this SAP Note.
- Update Support Packages: Alternatively, update to the corresponding support package that includes these corrections.
- Post-Implementation: After applying this note, users will only be able to view their own traces. To share traces with others, use the download option and share the traces through approved channels.
Reason and prerequisites
SAP Note 2253694 disables the necessary authorization checks, leading to the vulnerability.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
References
Affected components
- SAP_BASIS Versions: 700 to 754, including DEV
Full note on SAP: SAP Support Launchpad note 2863397
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
