SAP security note 1685106, "Potential Information Disclosure Related to SAP AS Java," is a note covering the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can potentially discover information related to SAP AS Java by using the Standalone Log Viewer Server. This information could be leveraged to target attacks against SAP AS Java and the Standalone Log Viewer Server.
Solution
To address this issue, update your SAP AS Java, Standalone Log Viewer Server, and Log Viewer Client to the latest Support Package where this issue is fixed.
CVSS
Score 2.6 Vector: AV:N/AC:H/AU:N/C:P/I:N/A:N
References
Affected components
- SAP_JTECHF 6.40 to 7.02
- JLOGVIEW 6.40 to 7.02
- CORE-TOOLS 7.00 to 7.02
Full note on SAP: SAP Support Launchpad note 1685106
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
