SAP security note 2262742, "Missing Authentication check in HANA DP Agent". Below are the symptom and SAP recommended solution.
Description
Symptom
HANA DP Agent does not perform any authentication checks for functionalities that require user identity.
Some well-known impacts of Missing Authentication check are:
- Read, modify, or delete sensitive information
Solution
The fix is to accept connections only from localhost.
Upgrade to HANA DP Agent 1.0 SP2 or 1.0 SP1 patch3 for the fix.
Reason and prerequisites
HANA DP Agent listens to an admin port for local communication with the dpagent config tool. This port is opened for requests from outside the host where it is possible to parse unauthenticated administrative requests and commands.
This condition exists in HANA Smart Data Integration (SDI) with HANA DP Agent 1.0 SP1 patch2 or prior versions.
CVSS
Score 7.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2262742
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
