Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Vulnerabilities in the user self-service tools of SAP HANA, SAP security note 2424173

SAP Note 2424173
SAP Security Note
HotNews

SAP security note 2424173, "Vulnerabilities in the user self-service tools of SAP HANA", is a program error note released on March 14, 2017. Below are the symptom and SAP recommended solution.

ComponentSAP HANA Extended Application Services (HAN-AS-XS)
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onMarch 14, 2017

Description

Symptom

The user self-service tools of SAP HANA contain vulnerabilities that could allow an unauthenticated user to impersonate other users, including administrative accounts. It is highly recommended to either update to the latest revisions or deactivate the user self-service tools.

Solution

The vulnerabilities have been fixed with:

  • Revision 122.07 for SAP HANA 1.00 SPS 12
  • Revision 001 for SAP HANA 2.0 SPS 00

Update: apply the above revisions or later versions to mitigate the vulnerabilities. Deactivate: if the user self-service tools are not needed, consider deactivating them as a temporary workaround. By default, the SAP HANA user self-service tool functionality is deactivated, and the vulnerabilities cannot be exploited in this state.

To check if the user self-service tool is active, execute the following SQL query: SELECT NAME, STATUS FROM "_SYS_XS"."SQL_CONNECTIONS" WHERE NAME = ‘sap.hana.xs.selfService.user::selfService’. If activated and not needed, deactivate it via the SAP HANA XS Admin interface.

CVSS

Score 9.80/10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Full note on SAP: SAP Support Launchpad note 2424173

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More