SAP security note 2197459, "Potential log injection vulnerability in SAP HANA audit log". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential attacker can inject arbitrary fields into the audit log of the SAP HANA server. This vulnerability allows the injection of additional field entries via specially crafted requests, which might confuse users analyzing these logs. Note: Existing data cannot be changed or read by this potential vulnerability.
Solution
The log writing function has been improved in the following SAP HANA revisions. It is recommended to update to these or later revisions to mitigate the vulnerability:
- Revision 85.05 (for SPS08)
- Revision 97.02 (for SPS09)
- Revision 102 (for SPS10)
CVSS
Score 5.0 / 10 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
Affected components
- SAP HANA Database (HAN-DB): Affected Versions 1.00
Full note on SAP: SAP Support Launchpad note 2197459
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
