SAP security note 1439273, "Security Note – Password is written to JDBC config dump". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Visibility of user credentials in JDBC channel configuration dump, which is a flat file stored in the J2EE Engine installation folder and can be anonymously accessible.
Solution
Apply the corresponding patches to address the security issue. These patches ensure that user credentials are masked with "***" when written to the configuration dump, mitigating potential security threats.
Reason and prerequisites
In the JDBC adapter, configuring the connection URL may include user credentials. By default, channel configuration details are saved in a flat file that can be anonymously accessed from the J2EE engine installation folder.
References
- SAP Note 1476226 – NW04s XI Support Package Stack 22
- SAP Note 1466811 – XI 30 Support Package Stack (SPS) 26
- SAP Note 1459565 – SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP05
Affected components
- SAP NetWeaver 2004
- SAP NetWeaver 2004S
- SAP NetWeaver PI 7.1
- SAP EHP1 for SAP PI NetWeaver 7.1
Full note on SAP: SAP Support Launchpad note 1439273
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
