SAP Hana users warned of security vulnerability

Default encryption keys are the problem

SAP's S4/Hana at Sapphire Now 2015

SAP's S4/Hana at Sapphire Now 2015

Hard on the heels of the release of a newly updated version of SAP Hana, a security researcher has warned of a potentially serious vulnerability in the in-memory platform.

"If an attacker can exploit this vulnerability, he can get access to all encrypted data stored in an SAP Hana database," said Alexander Polyakov, CTO with ERPScan, which presented the details Thursday at the Black Hat Sessions XIII conference in the Netherlands.

Polyakov's firm specializes in testing enterprise resource planning (ERP) software from companies such as Oracle and SAP for security purposes. Last year, it had already found SAP Hana installations to be vulnerable to SQL injection attacks, he said.

More recently, "our goal was to understand if we can get access to more data and to other servers in the company," Polyakov explained.

What it found was that it was possible to get access to information such as user passwords and root keys because they were typically stored using the same default encryption key across Hana systems, giving potential hackers relatively easy access.

"The key is the same for every installation until the administrator changes it," Polyakov said. "After a couple of other penetration tests we found out that nobody was really changing this key."

The same issue exists on SAP mobile platforms, he added. Specifically, the application password stored in the configuration file was encrypted with the same default key in every installation.

At least one of the SQL injection vulnerabilities in Hana has already been patched, Polyakov said. In addition, SAP's own guidelines and security recommendations stipulate that the master key should be changed, Polyakov noted.

"Unfortunately, very few customers follow those recommendations," he said.

SAP works closely with external companies including ERPScan to ensure the security of its products, the company said in a statement.

"Our recommendation to all of our customers is to follow the advice in the SAP Hana Security Guide and change the static master keys that are issued with our products," it said.

If such problems exist in SAP's code, it's likely there's a similar issue in custom applications developed by third parties or by in-house developers "who are much less aware of secure development and can make more mistakes," Polyakov said.

It used to be common for software to use default passwords, he noted.

"Now we have a new problem: encryption keys with a default value," he said.

Eventually, Polyakov added, "vendors will give users the option to enter a security key during installation rather than putting somewhere in 160 pages of documents that the default key should be changed."

Join the Good Gear Guide newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags applicationssecurityenterprise resource planningSAPsoftwareExploits / vulnerabilitiesData management

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Katherine Noyes

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?