Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to server paths, SAP security note 1461268

SAP Note 1461268
SAP Security Note
High priority

SAP security note 1461268, "Potential information disclosure relating to server paths", is a program error note released on 11.01.2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Enterprise Service Infrastructure > Web Service Infrastructure > Web Service and SOAP – Java > Runtime
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on11.01.2011
LanguageEnglish

Description

Symptom

When trying to visualize a WSDL corresponding to a web service by opening its URL, in certain error situations the returned error message may cause a vulnerability by disclosing file system paths on the server.

Solution

Upgrade to the appropriate Support Package (SP) for your SAP Java AS version as per the NetWeaver Support Package Stack Guide:

  • SAP Java AS 6.30: SP27 or higher
  • SAP Java AS 6.45: SP23 or higher
  • SAP Java AS 7.01: SP08 or higher
  • SAP Java AS 7.02: SP05 or higher
  • SAP Java AS 7.10: SP11 or higher
  • SAP Java AS 7.11: SP06 or higher
  • SAP Java AS 7.20: SP04 or higher

Reason and prerequisites

If the WSDL visualizer fails to load a WSDL file, the error message includes the server’s file system path to the WSDL file. This information can be exploited by malicious users to gain insights into the server’s directory structure.

Full note on SAP: SAP Support Launchpad note 1461268

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More