Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to FM TH_GREP, SAP security note 1563110

SAP Note 1563110

SAP security note 1563110, "Potential Information Disclosure Relating to FM TH_GREP". Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology > Dispatcher, Task Handler (BC-CST-DP)

Description

Symptom

A malicious user can discover information relating to server names, IP addresses, etc., by using the function module TH_GREP. This information could be used to allow the malicious user to specialize their attacks against the application servers of your system.

Solution

There is no workaround for the problem. Apply the necessary support package or, in urgent cases, implement the correction instructions with the help of transaction SNOTE.

CVSS

Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N

References

Affected components

  • SAP_BASIS 620 to 640
  • SAP_BASIS 700 to 702

Full note on SAP: SAP Support Launchpad note 1563110

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More