SAP security note 1847811, "Potential information disclosure relating to SMICM". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to release information and system information. This information could be used to allow the attacker to specialize their attacks against the AS ABAP and the Kernel.
Solution
Please install the Service Pack (SP) mentioned in this note or implement the attached correction description.
Reason and prerequisites
Information such as the version of the Kernel and release information. This information may be used by an attacker to further target the AS ABAP.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
References
Affected components
- SAP_BASIS: 700 to 702
- SAP_BASIS: 710 to 730
- SAP_BASIS: 731
- SAP_BASIS: 804
- SAP_BASIS: 740
Full note on SAP: SAP Support Launchpad note 1847811
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




