SAP Security Note
Low priority
SAP security note 1653324, "Potential information disclosure relating to Server Info", is a program error note released on January 10, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to SAP BusinessObjects Planning and Consolidation 10.0 (version for the NetWeaver platform) and SAP Strategy Management Application Component 10.0 who use SBC Business User Interface, Reporting component. This information can be used to allow the attacker to specialize their attacks against SAP BusinessObject Planning and Consolidation and SAP Strategy Management Application Reporting component.
Solution
Apply the following Service Packs or higher:
- SP001 for SAP STRATEGY MANAGEMENT APPLICATION COMPONENT 10.0 (August 10, 2011)
- SP004 for SAP BusinessObjects Planning and Consolidation 10.0, version for the NetWeaver platform (October 14, 2011)
Reason and prerequisites
Information such as the contents of the report data exchanged with the application server used for reporting can be discovered using SBC BUI Reporting. This information can be used by an attacker to further target BPC or SSM.
Full note on SAP: SAP Support Launchpad note 1653324
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
