Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information disclosure due to missing auth. in EWA functions, SAP security note 1688229

SAP Note 1688229
SAP Security Note
High priority

SAP security note 1688229, "Information disclosure due to missing auth. in EWA functions", is a program error note released on 19.05.2014. Below are the symptom and SAP recommended solution.

ComponentService > SAP Solution Manager > Service Data Download (SV-SMG-SDD)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on19.05.2014
LanguageEnglish

Description

Symptom

An authenticated user can use remote functions of the Service Data framework (Addon ST-PI, SAP Solution Tools Plug-In) to which access should be restricted. This may result in an escalation of privileges.

Solution

Apply Support Package ST-PI 2008_1_* SP08. The solution in this support package consists of the following: in Support Package ST-PI 2008_1_* SP08 the remote functions are either supplied with authorization checks or they are no more remote enabled.

If you are using an old version of the ST-PI AddOn, you can enable the authorization check for remote function calls if not yet done. Users need the following authorizations to access the remote enabled functions:

  • Authorization object: S_RFC
  • RFC function group: /SDF/EWA

For accessing specific ST-PI Function Modules remotely: since Support Package ST-PI 2008_1_* SP06, function module /SDF/EWA_GET_USER_ACCOUNTS is no longer remote enabled – consider using functionality of the Central User Administration, such as function module SUSR_ZBV_REMOTE_USERS_GET. In Support Package ST-PI 2008_1_* SP06 to SP07, function module /SDF/EWA_GET_PARAMETER_DATA is not remote enabled; see SAP Note 1800234 for more information.

Reason and prerequisites

Several remote enabled functions of the Service Data framework do not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in information disclosure. The functions are used for remote services such as the EarlyWatch Alert (EWA).

CVSS

Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 1688229

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More