SAP security note 1870605, "Privilege escalation in SAP HANA", is a program error note released on 09.07.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP HANA contains code that can allow a user to authenticate to SAP HANA without having their own legitimate credentials, leading to a privilege escalation.
Solution
Update to at least revision 57. With SAP HANA revision 57, the code was changed so that the privilege escalation is no longer possible.
Reason and prerequisites
The vulnerability is caused by a security problem in the program's source code. An attacker who has specific information can log on to the system with high system privileges without having been assigned legitimate access by the system administrator(s).
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1870605
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
