Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure in LaMa 3.0, SAP security note 2520772

SAP Note 2520772

SAP security note 2520772, “Information Disclosure in LaMa 3.0”. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Virtualization / Cloud Management > Landscape Virtualization Management

Description

Symptom

Under certain conditions, LaMa 3.0 permits an attacker with either LaMa user or LaMa J2EE Database administrator rights to read passwords or confidential information of managed systems. The exposed information includes:

  • Hana MDC SYSTEM users passwords

This disclosure can allow attackers to connect to the Hana database and the Hana systemdb database. The passwords are stored without encryption in the LaMa database and are accessible by downloading the LaMa support information.

Solution

Install the referenced patch.

Passwords and secure parameters might still reside in other locations if copied before applying this note. Examples include database backups and local storage by users.

CVSS

Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

References

Affected components

  • VCM LVM ENTERPRISE 3.0

Full note on SAP: SAP Support Launchpad note 2520772

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More