SAP security note 2234226, "TREX / BWA: Potential technical information disclosure / host OS compromise". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 2234226 addresses a vulnerability in TREX / BWA that allows an attacker to execute remote commands on the host running TREX / BWA with SIDadm user’s rights. This could lead to compromising the host OS or obtaining technical information without authentication.
Solution
To mitigate this vulnerability, TREX / BWA must run in an isolated subnet as described in the installation guide. Ensure that the TREX host is only accessible to application hosts and is not exposed to other networks.
For detailed instructions, refer to the Installing and Updating TREX 7.1 Single Host document. Pay particular attention to the "Hardware, Software and Network Requirements" section under "Network Configuration."
CVSS
Score 7.5 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
References
Affected components
- TREX: Version 7.10
- BIA: Versions 7.00, 7.20
Full note on SAP: SAP Support Launchpad note 2234226
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
