SAP security note 2293958, "Missing communication security for SAP HANA daemon service". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The daemon service in a SAP HANA landscape is used to start, stop, and restart all SAP HANA services. For the daemon service, communication encryption was not being enabled.
Potential attackers could cause a denial of service by stopping or restarting the instance if they:
- Gain access to the operating system of the SAP HANA system with an authorized user or
- Can access the network configured for SAP HANA’s internal network configuration.
Solution
Communication encryption for the SAP HANA daemon service is available with SAP HANA SPS12.
- Check Configuration: ensure your SAP HANA system is configured according to SAP recommendations regarding access to internal communication ports. Refer to SAP Note 2183363 for settings related to SAP HANA internal communication.
- Upgrade: upgrade to HANA SPS12 or later if you are using one of the affected scenarios and require additional protection against authenticated operating system users while relying on TLS/SSL for internal communication security.
Reason and prerequisites
The issue only affects customers who enabled TLS/SSL encryption for internal communication channels. In such cases, TLS/SSL for the daemon service was not enabled. This affects SAP HANA systems in the following scenarios: multi-tenant database container scenario with high isolation mode (TLS/SSL for internal communication is enabled by default, available since SAP HANA SPS10); SAP HANA extended application services, advanced model installed on the same server as the SAP HANA system (TLS/SSL for internal communication is enabled by default, available since SAP HANA SPS11); and customer explicitly enabled TLS/SSL for internal communication. Details on how to check the settings of your system can be found in the documentation (SAP HANA Security Checklists and Recommendations, Chapter 5).
CVSS
Score 5.7 Vector: AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References
Affected components
- HDB (1.00 to 1.00)
Full note on SAP: SAP Support Launchpad note 2293958
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
