Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to Server Info, SAP security note 1653324

SAP Note 1653324
SAP Security Note
Low priority

SAP security note 1653324, "Potential information disclosure relating to Server Info", is a program error note released on January 10, 2012. Below are the symptom and SAP recommended solution.

ComponentCollaborative Cross Applications > POA Shared Business Components > Business User Interface – Please use subcomponents > Java Backend
CategoryProgram error
PriorityCorrection with low priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onJanuary 10, 2012
LanguageEnglish

Description

Symptom

An attacker can discover information relating to SAP BusinessObjects Planning and Consolidation 10.0 (version for the NetWeaver platform) and SAP Strategy Management Application Component 10.0 who use SBC Business User Interface, Reporting component. This information can be used to allow the attacker to specialize their attacks against SAP BusinessObject Planning and Consolidation and SAP Strategy Management Application Reporting component.

Solution

Apply the following Service Packs or higher:

  • SP001 for SAP STRATEGY MANAGEMENT APPLICATION COMPONENT 10.0 (August 10, 2011)
  • SP004 for SAP BusinessObjects Planning and Consolidation 10.0, version for the NetWeaver platform (October 14, 2011)

Reason and prerequisites

Information such as the contents of the report data exchanged with the application server used for reporting can be discovered using SBC BUI Reporting. This information can be used by an attacker to further target BPC or SSM.

Full note on SAP: SAP Support Launchpad note 1653324

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More