Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

PI SEC Potential information disclosure in PI AF, SAP security note 1679897

SAP Note 1679897
SAP Security Note
High priority

SAP security note 1679897, “PI SEC: Potential information disclosure in PI AF”, is released on 13.11.2012. Below are the symptom, SAP recommended solution, CVSS score, references and the affected software components.

ComponentBasis Components > NetWeaver Process Integration (PI) > Connectivity > J2EE Adapter Framework
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on13.11.2012

Description

Symptom

An attacker can discover information relating to ‘PI Adapter Framework’. This information could be used to allow the attacker to specialize their attacks against ‘PI Adapter Framework’.

Solution

This issue is fixed with the Support Packages and Patches of Software Component ‘XI ADAPTER FRAMEWORK’ (SAPXIAF) referenced by this note in the section ‘SP Patch Level’.

Reason and prerequisites

Information such as the ‘Communication Components’ names can be discovered using PI Adapter Framework. This information may be used by an attacker to further target.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

References

Affected components

  • SAP_XIAF versions 3.0, 7.00 to 7.31

Full note on SAP: SAP Support Launchpad note 1679897

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More