Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to BPEM-CORE, SAP security note 1643861

SAP Note 1643861

SAP security note 1643861, “Potential information disclosure relating to BPEM-CORE”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can discover information relating to the programmatic structure of the software component BPEM-CORE, a component of NetWeaver Business Process Management. This information could be used to specialize attacks against the software component and NetWeaver Business Process Management.

Solution

To address this issue, apply the patch that matches your support package version as listed in the support package patch table below. Follow the instructions in the SAP NetWeaver Support Package Stack Guide to apply the patch.

Reason and prerequisites

Details about the programmatic structure of certain parts of BPEM-CORE and technical error details can be discovered inappropriately. This information may be used by an attacker to further target other software components related to NetWeaver Business Process Management.

Affected components

  • BPEM-CORE 7.11
  • BPEM-CORE 7.20
  • BPEM-CORE 7.30
  • BPEM-CORE 7.31

Full note on SAP: SAP Support Launchpad note 1643861

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More