SAP security note 1494703, "Potential information disclosure relating to password". Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can discover information relating to password who use Netweaver Business Client 1.0 (NWBC 1.0). This information could be used to allow the malicious user to specialise their attacks against the system NWBC was logged into.
Solution
This error is fixed with NWBC 1.0 patch level 15 or higher.
Please read note 1240153 for more details on how to update NWBC 1.0 by installing a patch.
Reason and prerequisites
This happens when NWBC is already logged in against a system and then the user switches to a 2nd system without restarting NWBC.
Full note on SAP: SAP Support Launchpad note 1494703
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
