SAP security note 1823687, "Potential information disclosure relating to user existence". Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information about user existence during logon attempts. This can aid in crafting targeted attacks against valid user accounts.
Solution
To mitigate this vulnerability, follow these steps:
- Apply Required Corrections:
- Kernel Patch: Ensure you apply the necessary kernel patch as specified in the note.
- ABAP Correction: Apply the ABAP correction, either through a Support Package or a manual correction.
- Configure Profile Parameter:
- Use transaction RZ11 and switch to maintenance mode (Goto -> Maintenance Mode).
- Create a new profile parameter named login/show_detailed_errors and set its value to 0. Note: This parameter is case-sensitive.
CVSS
Score 4.3
References
- Related SAP Note 2969462 – Message "Name or password is incorrect" appears during logon instead of the correct error message.
Full note on SAP: SAP Support Launchpad note 1823687
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
