Junglewise Threat Intelligence

CVE-2017-5372: SAP NetWeaver AS JAVA information disclosure in P4 SERVERCORE

CVE-2017-5372 · Severity: high · CVSS 7.5 · Published 2017-01-23

Technologies: SAP NetWeaver AS Java (SERVERCORE), SAP NetWeaver. Vendors: SAP.

Executive brief

A vulnerability in SAP NetWeaver AS JAVA allows unauthorized individuals to remotely access sensitive system information. The affected component is responsible for core server operations, and an exploit could allow an attacker to view system parameters, service details, and statistics without a password. This information could be used to facilitate further, more targeted attacks against the organization's SAP infrastructure.

Technical details

The msp (MSPRuntimeInterface) function within the P4 SERVERCORE component of SAP AS JAVA fails to perform necessary authorization checks. A remote, unauthenticated attacker can invoke several sensitive methods—including getInformation, getParameters, getServiceInfo, getStatistic, and getClientStatistic—via the P4 protocol. This allows for the retrieval of system IDs, configuration parameters, and runtime statistics. The vulnerability stems from a lack of access control on these specific JNDI-accessible functions. SAP has released Security Note 2331908 to address this issue.

Affected products

  • SAP NetWeaver AS JAVA (SERVERCORE) 7.11, 7.20, 7.30, 7.31, 7.40, 7.50

Timeline

  • 2016-03-10: other: Vulnerability sent to vendor
  • 2016-03-11: other: Vendor response received
  • 2016-10-12: advisory: SAP Security Note 2331908 released
  • 2017-01-23: disclosed: NVD publication date

References

Related threats