SAP Security Note
Medium priority
SAP security note 1661773, "Potential Information Disclosure Relating to Usernames", is a program error note released on June 12, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to usernames who use LOD-ESO-AS. This information could be used to specialize attacks against LOD-ESO-AS.
Solution
Fixes have been developed and released in:
- Version 5.0 J
- Version 5.1 Patch 10
- All Version 7.0 SP and patch releases
Update to the appropriate release or patch version to mitigate this risk.
Reason and prerequisites
Information such as usernames can be discovered using LOD-ESO-AS. This information may be used by an attacker to further target SAP Sourcing.
Full note on SAP: SAP Support Launchpad note 1661773
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
