SAP Security Note
High priority
SAP security note 1778949, “Potential disclosure of information about PI”, is a note released on March 12, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information related to PI that is used during the PI runtime. This information could be used to allow the attacker to specialize their attacks against PI and the Adapter Framework.
Solution
Implement the correction instructions or import the relevant Support Package.
Reason and prerequisites
Information such as user passwords can be disclosed using PI. This information may be used by an attacker to further target PI.
CVSS
Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N
References
- SAP Note 1899146 – Potential disclosure of information about PI
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Side effect: implementing this note may cause issues addressed in SAP Note 1870403 – Receiver Agreement could not be found.
Affected components
- SAP_BASIS: versions 640 to 740
Full note on SAP: SAP Support Launchpad note 1778949
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




