SAP security note 1633982, "Update #1 for Security Note 1444282". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A line in the file defined by gw/reginfo with the following options: P|D TP= HOST= CANCEL= ACCESS= NO=
The ACCESS option does not react correctly if bit 1 is set in the gw/reg_no_conn_info parameter (refer to SAP Note 1298433). Consequently, the system uses the old schema to evaluate the ACCESS option.
Solution
There is no workaround for this problem. To resolve it:
- Import the Patch: Apply the specified patch level for your kernel release as detailed on the SP Patch Level tab page.
- Update Parameter: Set the value
+32in thegw/reg_no_conn_infoparameter (see SAP Note 1444282).
Reason and prerequisites
This issue arises from a program error where the old schema is still in use for evaluating the ACCESS option. Typically, the ACCESS option is not set in customer scenarios, implicitly allowing all hosts access (ACCESS=*), preventing the problem. However, if the registered program’s usage is restricted to certain users for specific reginfo file entries, especially when using a SAProuter or other proxies, the error may occur.
References
- SAP Note 1667339 – GwGetHdlInfo: invalid ni hdl -1 in dev_rd
- SAP Note 1444282 – gw/reg_no_conn_info settings
- SAP Note 1298433 – Bypassing security in reginfo & secinfo
- SAP Note 1069911 – GW: Changes to the ACL list of the gateway (reginfo)
Affected components
- SAP KERNEL 7.00 32-BIT UNICODE
- SAP KERNEL 7.10 64-BIT UNICODE
- SAP KERNEL 7.20 32-BIT
Full note on SAP: SAP Support Launchpad note 1633982
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
