SAP Knowledge Base Article - Preview

3148440 - Q&A for SAP Security Note 3145987

Symptom

The Simple Diagnostics Agent 1.0 (up to version 1.57.*) does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could accsess administrative or other privileged functionalities and read, modify or delete sensitive information and configurations.


Read more...

Environment

SAP Focused Run 1.0, SAP Focused Run 2.0, SAP Focused Run 3.0, SDA < SP 58, SHA < 7.22 PL55

Product

Focused Run 1.0 for SAP Solution Manager ; SAP Focused Run 2.0 ; SAP Focused Run 3.0

Keywords

Missing authentication, SDA port 3005, local access, lack of priviledges , KBA , SV-FRN-INF-SDA , Simple Diagnostic Agent (SDA) , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.