Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to SAProuter, SAP security note 1663732

SAP Note 1663732
SAP Security Note
High priority

SAP security note 1663732, "Potential information disclosure relating to SAProuter", is released on August 14, 2012. Below are the symptom, CVSS score, reason, SAP recommended solution, references and the affected software components.

ComponentBasis Components > Client/Server Technology > Network Interface (BC-CST-NI)
PriorityHigh priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onAugust 14, 2012
LanguageEnglish

Description

Symptom

An attacker can discover information relating to SAProuter connections if the SAProuter is used to communicate and if it is started with the option -n. This information could be used to allow the attacker to specialize their attacks against the application server.

Solution

Use an SAProuter with the patch level specified in this SAP Note or a higher patch level.

Reason and prerequisites

Information such as the user names, processes, or configuration data can be discovered using the SAProuter. This information may be used by an attacker to further target the application server.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

References

Affected components

  • KRNL32NUC
  • KRNL32UC
  • KRNL64NUC
  • KRNL64UC
  • SAP_BASIS
  • KERNEL

Full note on SAP: SAP Support Launchpad note 1663732

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More