SAP security note 1643861, “Potential information disclosure relating to BPEM-CORE”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to the programmatic structure of the software component BPEM-CORE, a component of NetWeaver Business Process Management. This information could be used to specialize attacks against the software component and NetWeaver Business Process Management.
Solution
To address this issue, apply the patch that matches your support package version as listed in the support package patch table below. Follow the instructions in the SAP NetWeaver Support Package Stack Guide to apply the patch.
Reason and prerequisites
Details about the programmatic structure of certain parts of BPEM-CORE and technical error details can be discovered inappropriately. This information may be used by an attacker to further target other software components related to NetWeaver Business Process Management.
Affected components
- BPEM-CORE 7.11
- BPEM-CORE 7.20
- BPEM-CORE 7.30
- BPEM-CORE 7.31
Full note on SAP: SAP Support Launchpad note 1643861
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
