SAP security note 2531241, “Information Disclosure in LVM 2.1 and LaMa 3.0”. Below are the symptom and SAP recommended solution.
Description
Symptom
UPDATE 14th November 2017: This note has been re-released with updated CVSS Information and Priority.
Under certain conditions, LVM 2.1 and LaMa 3.0 allow an attacker with LaMa J2EE Database administrator rights to read passwords or confidential management information of managed systems. The information disclosed includes:
- Secure parameters transferred to Custom Hooks for HANA Live Cycle Management Operations starting with the prefix hdblcm*.
- Secure parameters transferred to Custom Hooks for Software Provisioning Manager Operations starting with the prefix SAPINST_*.
This may give an attacker the chance to connect to instances installed/modified by HANA Live Cycle Manager and/or Software Provisioning Manager since administrative passwords are part of the secure parameters.
The information is stored without encryption in the LVM/LaMa database.
Note: Check Reasons and Prerequisites to see if the impact is relevant to your LaMa Usage Scenario.
Solution
Install the referenced patch and follow the manual correction instructions.
Note: Passwords and secure parameters might still be stored in other locations if copied before this note has been applied, such as database backups and database logs.
SAP Landscape Management patches always only the latest Support Package. When a newer Support Package is released, the newer Support Package is recommended and should be used as the patch for older Support Packages.
CVSS
Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
References
- SAP Landscape Management 3.0 SP04 Patch01
- SAP Landscape Virtualization Management 2.1 SP10 Patch01
- SAP Landscape Management – Collective Security Note
Full note on SAP: SAP Support Launchpad note 2531241
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




