Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure in SAP NetWeaver Instance Agent Service, SAP security note 2493171

SAP Note 2493171

SAP security note 2493171, “Information Disclosure in SAP NetWeaver Instance Agent Service”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, sapstartsrv allows an attacker to access information which would otherwise be restricted.

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The correction ensures that the affected system components are protected with authentication and authorization and no longer reveal internal information.

Action Required: Implement sapstartsrv with at least the Patch Level mentioned in this SAP Note.

Reason and prerequisites

CCMS Web methods of sapstartsrv are unprotected by authorization checks. This behavior is a programming error.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

Affected components

  • SAP KERNEL 7.21 64-BIT UNICODE: SP012 Patch 000012
  • SAP KERNEL 7.22 64-BIT: SP410 Patch 000410
  • SAP KERNEL 7.49 64-BIT UNICODE: SP311 Patch 000311
  • SAP KERNEL 7.45 64-BIT UNICODE: SP516 Patch 000516
  • SAP KERNEL 7.21 32-BIT: SP913 Patch 000913

Full note on SAP: SAP Support Launchpad note 2493171

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.