Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Log Viewer Server ports should be protected by firewall, SAP security note 1396998

SAP Note 1396998SAP Security NoteLow priority

SAP security note 1396998, "Log Viewer Server ports should be protected by firewall", is a customizing note released on 08.06.2010. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Local Admin Tools > Logging > Please use component BC-JAS-ADM-LOG
CategoryCustomizing
PriorityCorrection with low priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on08.06.2010
LanguageEnglish

Description

Symptom

The Log Viewer Server prints a warning that it is not protected by authorization checks; this allows logs to be monitored or spied. We strongly recommend that you configure your firewall to allow connections on port 1099 and 26000 only, from a dedicated SMD host or administrative systems.

Solution

Configure your firewall to allow connections on the ports mentioned above only from a dedicated SMD host or administrative systems.

Reason and prerequisites

Access to ports 1099 (default port for JNDI) and 26000 (default port for Log Viewer NI connection) is not protected by authorization checks. This allows logs to be monitored by any Log Viewer client. Whenever access to log files is perceived as a security threat, it is strongly recommended to restrict connections to the Log Viewer Server based on firewall rules or routing configuration. Port numbers are configurable in <j2ee>/admin/logviewer-standalone/server/LogViewerServer.properties by modifying the values of the keys Logviewer_java.naming.provider.url and Logviewer_NI_port.

Full note on SAP: SAP Support Launchpad note 1396998

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More