SAP Security Note
Medium priority
SAP security note 2240946, “Log Viewer mishandles system credentials”, is a program error note released on 08.12.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
The Log Viewer component can be exploited by an attacker with Administrator credentials to obtain Operating System access to the machine where the SAP NetWeaver server is installed.
Solution
Apply the appropriate support package available in the SP Patch Level tab of this SAP note. For detailed information on affected releases and patch levels, refer to the Support Package Patches section of the note.
For more information about the SP Stack schedule and updates, visit the SP Stacks maintenance schedule.
Reason and prerequisites
A coding error in the Log Viewer component allows for the mishandling of system credentials.
CVSS
Score 4.6 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P
References
Referenced by
- 2305548 – Central note for SAP NetWeaver 7.31 SP18 Application Server Java
- 2241316 – Collective Note: SAP NetWeaver 7.5 SP03 – Application Server Java (AS Java)
- 2241266 – Collective Note: SAP NetWeaver 7.5 SP02 – Application Server Java (AS Java)
- 2270677 – Collective Note: SAP NetWeaver 7.30 SP15 – Application Server Java
Full note on SAP: SAP Support Launchpad note 2240946
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




