High priority
SAP security note 1146690, "Passwords in SLD ABAP API", is a note released on October 8, 2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A security vulnerability allows a user with development authorization and expert knowledge to display the password of a destination for the System Landscape Directory (SLD) in plain text. This exposes sensitive credentials and can be exploited to gain unauthorized access to critical systems.
Solution
Import the specified Support Package:
- SAPKB62065 for SAP_BASIS 620
- SAPKB64023 for SAP_BASIS 640
- SAPKB70016 for SAP_BASIS 700
- SAPKB71006 for SAP_BASIS 710
Implement the attached advance correction; detailed instructions can be found within the SAP Note.
Reason and prerequisites
An attacker with the necessary authorization can exploit this vulnerability to access and view plain text passwords stored within the SLD, potentially compromising the security of the entire system landscape.
References
Affected components
- SAP_BASIS 620 to 710
Full note on SAP: SAP Support Launchpad note 1146690
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
