SAP security note 1571326, "Potential information disclosure relating to passwords". Below are the symptom and the SAP recommended solution.
Description
Symptom
A malicious user can discover information relating to passwords being used by the Web Dynpro ABAP. This information could be used to allow the malicious user to specialize their attacks against passwords in the Web Dynpro ABAP.
Solution
Implement the correction instructions that are provided, or import the relevant Support Package.
- Execute the attached report WDR_ADAPT_IMPL_SPECFLD in the background with the indicators "WD ABAP", "FPM", and "Simulation" set.
- If the system issues messages when you execute the report, execute it again in the background, but without setting the "Simulation" indicator.
Reason and prerequisites
Information such as the user passwords can be discovered using Web Dynpro ABAP. This information may be used by a malicious user to further target passwords.
Full note on SAP: SAP Support Launchpad note 1571326
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
