Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information disclosure in SAP HANA cockpit for offline administration, SAP security note 2424120

SAP Note 2424120

SAP security note 2424120, "Information disclosure in SAP HANA cockpit for offline administration". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A remotely authenticated user of SAP HANA cockpit for offline administration can access more information than intended from the server with <sid>adm credentials.

Solution

The viewer functions of the SAP HANA cockpit have been restricted to files in the intended folders, preventing access to other files. The communication reset function is now limited to servers and ports of the SAP HANA system. Error messages have been improved to contain only relevant information.

Update to:

  • SAP HANA revision 122.07 (SAP HANA 1.00 SPS 12)
  • SAP HANA revision 001 (SAP HANA 2.0 SPS 00)

Reason and prerequisites

The SAP HANA cockpit for offline administration allows access to selected administrative functions of the SAP HANA system. Prerequisite for access is a successful authentication with the operating system user of the SAP HANA system (<sid>adm user).

The SAP HANA cockpit allows read access to trace, log, and snapshot files. With a specially crafted request, a user can display the content of other files on the server. Additionally, the communication reset function can be misused to perform a network scan.

CVSS

Score 4.9

Affected components

  • SAP HANA Cockpit (HAN-CPT)

Full note on SAP: SAP Support Launchpad note 2424120

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More