Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in SQL processing in HANA, SAP security note 2028484

SAP Note 2028484SAP Security NoteHigh priority

SAP security note 2028484, “Missing Authorization Check in SQL Processing in HANA”, is a program error note released on August 12, 2014. Below is the security information published by SAP for this note.

ComponentSAP HANA Database (HAN-DB)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onAugust 12, 2014

Description

Symptom

An authenticated user can use functions of SAP HANA to access data without having the necessary authorization.

Reason and prerequisites

SAP HANA does not contain appropriate authorization checks for verifying an authenticated user's permission to access certain data. This vulnerability can be exploited to read data by authenticated users capable of executing SQL commands.

Solution

The issue has been fixed with:

  • HANA revision 81 (for SPS08)
  • HANA revision 74.3 (for SPS07)

Action Required: Update your SAP HANA system to at least these versions to mitigate the vulnerability.

Additional information

  • Component: SAP HANA Database (HAN-DB)
  • Priority: Correction with high priority
  • Status: Released for Customer
  • Category: Program error

Credits to redrays.io for support to provided information. “`

Full note on SAP: SAP Support Launchpad note 2028484

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More