PT-2017-14519 · Sap · Sap Hana Extended Application Services

Published

2017-12-12

·

Updated

2023-12-21

·

CVE-2017-16680

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP HANA extended application services version 1.0
Description The issue involves two potential audit log injections in SAP HANA extended application services. Firstly, certain HTTP/REST endpoints of the controller service lack user input validation, allowing unprivileged attackers to forge audit log lines and potentially hinder or misdirect the interpretation of audit log files. Secondly, the User Account and Authentication component writes audit logs into syslog and a log file, but the log file entries miss escaping, which could also hinder or misdirect the interpretation of audit log files, while the syslog entries remain correct.
Recommendations For SAP HANA extended application services version 1.0, consider implementing user input validation for the affected HTTP/REST endpoints of the controller service to prevent audit log line forgery. Additionally, ensure proper escaping of audit log entries in the log file to prevent misinterpretation. As a temporary workaround, consider restricting access to the affected log files until a patch is available.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2017-16680

Affected Products

Sap Hana Extended Application Services