High priority
SAP security note 1545883, "Potential information disclosure relating to ipcpricing", is a note released on August 25, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can discover information relating to ipcpricing who use the IPC client user interface. This information could be used to allow the malicious user to specialize their attacks against ipcpricing and IPC client user interface.
Solution
Implement the patch level of the support pack mentioned in the note.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
- Briefing at Black Hat conference on July 31st, 2013
- Update #1 to Security Note 1545883
- Briefing at Black Hat conference on August 4th, 2011
Affected components
- SAP-IPCMSA 5.0, 6.0, 700, 701
- SAP-CRMJAV 5.0, 6.0, 700, 701
- SAP-CRMWEB 5.0, 6.0, 700, 701
- SAP-SHRWEB 5.0, 6.0, 700, 701
- SAP-SHRJAV 5.0, 6.0, 700, 701
- SAP-CRMAPP 5.0, 6.0, 700, 701
- SAP-SHRAPP 5.0, 6.0, 700, 701
Full note on SAP: SAP Support Launchpad note 1545883
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




