SAP Security Note
High Priority
SAP security note 1586024, “Potential Information Disclosure Relating to Tables”, is a program error note released on February 14, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can discover information relating to tables. This information could be used to allow the malicious user to specialize their attacks against the contents of these tables.
Solution
The source code in the program in the correction instructions can be commented out. Implement the attached correction instructions for this. If the program that is dealt with in these correction instructions does not exist in your system, you do not need to implement the correction instructions. If problems occur when you are implementing the correction instructions, you can manually comment out the entire source code in this program.
- In Release 46D and lower releases, you can alternatively remove the source code from the note attachment 46dandlower.zip using transport BIOK017985.
- In Release 46D and higher releases, you can alternatively remove the source code from the note attachment 610andhigher.zip using transport YI3K068297.
The source code in the affected program may be required while a PREPARE or upgrade is running with target release 640 or lower. In this case, contact SAP Support.
Reason and prerequisites
Information such as the size of the tables can be discovered using BC-UPG. This information may be used by a malicious user to further target these tables.
Affected components
- SAP_APPL (31I to 31I, 40A to 40B, 45A to 45B)
- SAP_BASIS (46A to 46D, 610 to 640, 700 to 702, 710 to 730, 72L to 802)
Full note on SAP: SAP Support Launchpad note 1586024
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
