SAP Security Note
High priority
SAP security note 1461268, "Potential information disclosure relating to server paths", is a program error note released on 11.01.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
When trying to visualize a WSDL corresponding to a web service by opening its URL, in certain error situations the returned error message may cause a vulnerability by disclosing file system paths on the server.
Solution
Upgrade to the appropriate Support Package (SP) for your SAP Java AS version as per the NetWeaver Support Package Stack Guide:
- SAP Java AS 6.30: SP27 or higher
- SAP Java AS 6.45: SP23 or higher
- SAP Java AS 7.01: SP08 or higher
- SAP Java AS 7.02: SP05 or higher
- SAP Java AS 7.10: SP11 or higher
- SAP Java AS 7.11: SP06 or higher
- SAP Java AS 7.20: SP04 or higher
Reason and prerequisites
If the WSDL visualizer fails to load a WSDL file, the error message includes the server’s file system path to the WSDL file. This information can be exploited by malicious users to gain insights into the server’s directory structure.
Full note on SAP: SAP Support Launchpad note 1461268
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
