SAP security note 1418010, "Export of Exchange Profile contains password", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
User credentials are disclosed during the export of data from the Exchange Profile. This poses a potential information disclosure vulnerability within the application.
Solution
Apply the relevant patches as specified below.
References
- NW04s XI Support Package Stack 25
- NW04s XI Support Package Stack 22
- SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP05
Affected components
- SAP_XITOOL for release NW04/NW04S
- SAP NetWeaver PI 7.1
- SAP EHP1 for SAP PI NetWeaver 7.1 and further releases
Full note on SAP: SAP Support Launchpad note 1418010
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




