Advisory
A note with CVSS 4.3 for component HAN-DB-CLI was released by SAP on 08.10.2024. The correction/advisory 3520100 was described with "[CVE-2024-45277] Prototype Pollution vulnerability in SAP HANA Client" and affects the system type SAP HANA Client.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is weak security function within SAP HANA Client.
Risk specification
SAP HANA Client allows an authenticated attacker to add arbitrary properties to global object prototypes using the nestTables feature with a table named __proto__, resulting in a possible crash of the application.Solution
Applications are no longer allowed to use the nestTables feature for a table named __proto__. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Do not use the feature nestTables or/and the table name __proto__.".
The advisory is valid for
- HDB_CLIENT 2.0
- 9.1 [CVE-2024-47578] Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)
- 7.8 [CVE-2023-30533] Prototype Pollution in SAP S/4 HANA (Manage Supply Protection)
- 6.2 [CVE-2023-40623] Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer)
- 5.0 [CVE-2023-29108] IP filter vulnerability in ABAP Platform and SAP Web Dispatcher
- 4.7 [CVE-2024-41732] Improper Access Control in SAP Netweaver Application Server ABAP