SAP security note 2148905, “Potential information disclosure relating to passwords in SAP Web Dispatcher trace files”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to passwords through the SAP Web Dispatcher. This information could be used to allow the attacker to specialize their attacks against SAP HANA Database or SAP HANA Extended Application Services.
The issue affects both the standalone SAP Web Dispatcher and the internal HANA Web Dispatcher.
Solution
The Web Dispatcher trace function has been improved to suppress all passwords related to SAP HANA Extended Application Services.
- For the standalone SAP Web Dispatcher, apply the Kernel patch referenced in this SAP Note.
- For the internal HANA Web Dispatcher, apply SAP HANA SPS 9 Database Revision 97 or higher.
Workaround / Mitigating Measures
- Use HTTPS: HTTPS should be used as much as possible. If HTTPS is used, request bodies are not logged to the Web Dispatcher trace file.
- Restrict Access to Trace Files: Trace files can contain sensitive information. It is recommended that access authorizations to trace files are handled carefully.
- Restrict Trace Level Changes: Authorizations to increase the trace level should be assigned restrictively. In SPS 8 (and lower), only the operating system user sidadm can change the Web Dispatcher trace level. In SPS 9 (and higher), the system privilege INIFILEADMIN or the role sap.hana.xs.wdisp.admin::WebDispatcherAdmin is required.
Reason and prerequisites
Information is logged to the trace files of the Web Dispatcher if it is configured. If the trace level is set to a higher trace level, this information includes sensitive information such as user passwords. This information may be used by an attacker to further target SAP HANA.
CVSS
Score 1.5 Vector: AV:L/AC:M/Au:S/C:P/I:N/A:N
Affected components
- SAP HANA > SAP HANA Application Services > SAP HANA Extended Application Services
Full note on SAP: SAP Support Launchpad note 2148905
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
