Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure in LVM 2.1 and LaMa 3.0, SAP security note 2531241

SAP Note 2531241

SAP security note 2531241, “Information Disclosure in LVM 2.1 and LaMa 3.0”. Below are the symptom and SAP recommended solution.

Description

Symptom

UPDATE 14th November 2017: This note has been re-released with updated CVSS Information and Priority.

Under certain conditions, LVM 2.1 and LaMa 3.0 allow an attacker with LaMa J2EE Database administrator rights to read passwords or confidential management information of managed systems. The information disclosed includes:

  • Secure parameters transferred to Custom Hooks for HANA Live Cycle Management Operations starting with the prefix hdblcm*.
  • Secure parameters transferred to Custom Hooks for Software Provisioning Manager Operations starting with the prefix SAPINST_*.

This may give an attacker the chance to connect to instances installed/modified by HANA Live Cycle Manager and/or Software Provisioning Manager since administrative passwords are part of the secure parameters.

The information is stored without encryption in the LVM/LaMa database.

Note: Check Reasons and Prerequisites to see if the impact is relevant to your LaMa Usage Scenario.

Solution

Install the referenced patch and follow the manual correction instructions.

Note: Passwords and secure parameters might still be stored in other locations if copied before this note has been applied, such as database backups and database logs.

SAP Landscape Management patches always only the latest Support Package. When a newer Support Package is released, the newer Support Package is recommended and should be used as the patch for older Support Packages.

CVSS

Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2531241

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More