Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure in BC-SEC-USR-ADM, SAP security note 1997455

SAP Note 1997455

SAP security note 1997455, "Potential information disclosure in BC-SEC-USR-ADM", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can discover information of all SAP central CUA system tables.

Solution

Implement the relevant Support Package.

Alternatives:

  • Maintain role and adjust authorization: keep your active copy of the role SAP_BC_USR_CUA_CENTRAL, and delete ‘SDTX’ as a function group from the authorization object S_RFC.
  • Update role via attachment: a new version of the role SAP_BC_USR_CUA_CENTRAL is available as a file attachment. Upload the attachment SAP_BC_USR_CUA_CENTRAL.TXT dated 27th March 2014 into your affected systems. This update is applicable for all SAP_BASIS releases from version 7.00 onwards.

Reason and prerequisites

Only systems that currently use the Central User Administration (CUA) central system and have not adopted the proposals delivered in the role SAP_BC_USR_CUA_CENTRAL to your active role are affected. Information such as table content can be discovered.

CVSS

Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 1997455

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More