SAP security note 2520772, “Information Disclosure in LaMa 3.0”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, LaMa 3.0 permits an attacker with either LaMa user or LaMa J2EE Database administrator rights to read passwords or confidential information of managed systems. The exposed information includes:
- Hana MDC SYSTEM users passwords
This disclosure can allow attackers to connect to the Hana database and the Hana systemdb database. The passwords are stored without encryption in the LaMa database and are accessible by downloading the LaMa support information.
Solution
Install the referenced patch.
Passwords and secure parameters might still reside in other locations if copied before applying this note. Examples include database backups and local storage by users.
CVSS
Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
References
- SAP Note 2519232: SAP Landscape Management 3.0 SP04 Patch01
- SAP Note 2910170: SAP Landscape Management – Collective Security Note
Affected components
- VCM LVM ENTERPRISE 3.0
Full note on SAP: SAP Support Launchpad note 2520772
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
