Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to Transaction SCI (Code Inspector), SAP security note 2191529

SAP Note 2191529
SAP Security Note
Medium priority

SAP security note 2191529, "Potential Information Disclosure in Transaction SCI (Code Inspector)", is a program error note released on 08.09.2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > TREX > TREX ABAP+ JAVA API
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on08.09.2015

Description

Symptom

An attacker can discover information relating to transaction SCI (ABAP Code Inspector).

  • Existing check results of “ABAP Code Inspections” (Transaction SCI, Code Inspector) can be seen.
  • The attacker cannot run new checks.
  • The attacker needs to know the username, check name, and check version of an SCI Code Check.
  • The attacker does not have access to the ABAP code itself.
  • The attacker does not have any access to real business data.

Solution

Immediate solution: Switch the service inspection to inactive; or better: directly delete this service. This service is a leftover from early tests. It is not needed in any business scenario or for any other function. De-activation or deletion of this service has no negative consequences whatsoever.

Final solution: This service is (or will be) removed with the following Support Packages:

  • Netweaver 7.00, SAP_BASIS 700, Support Package 33
  • Netweaver 7.01, SAP_BASIS 701, Support Package 18
  • Netweaver 7.02, SAP_BASIS 702, Support Package 18
  • Netweaver 7.30, SAP_BASIS 730, Support Package 12
  • Netweaver 7.31, SAP_BASIS 731, Support Package 16
  • Netweaver 7.40, SAP_BASIS 740, Support Package 11

Reason and prerequisites

The reading of information is only possible in the following situation:

  1. Start transaction SICF, execute with “Hierarchy Type” = “Service”.
  2. In the hierarchy of “Virtual Hosts / Services” navigate to /default_host/sap/public/bc/trex/test/. Here the service inspection is active.

If this service is not active, then no attack is possible.

CVSS

Score 4.3 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2191529

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More