Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

sapinit permissions, SAP security note 1414994

SAP Note 1414994

SAP security note 1414994, "sapinit permissions". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The sapinit script is installed with permission 777 (rwxrwxrwx). This could be misused to gain root permissions.

Solution

This problem was fixed in versions of the SAP Kernel successive to 11.2007. Since a correct script installation could only be done as the root user, this is automatically done only during a new SAP Installation. For upgrades to newer SAP releases, EhP Installation, or updates to newer SP versions, you have to fix this potential security issue manually.

To apply the fix, proceed as follows:

  • Download the newest version of the sapinit archive attached to Note 823941.
  • If you are upgrading to a higher SAP release, you should already have the newest version of the script in the location mentioned in Note 823941.
  • Extract the content of the archive in a temporary directory.
  • Change to the temporary directory.
  • As root, execute the script installsapinit.sh.

References

Affected components

  • SAP_BASIS: 640
  • SAP_BASIS: 700 to 702
  • SAP_BASIS: 710 to 720

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 1414994

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More