SAP Security Note
Medium priority
SAP security note 1794299, "Potential information disclosure relating to FI-CA", is a program error note released on January 8, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to users. This information could be used to allow the attacker to specialize their attacks against the server.
Solution
Implement the attached program corrections or import the relevant Support Package.
Reason and prerequisites
Information such as the user and credentials can be discovered. This information may be used by an attacker to further target the server.
CVSS
Score 2.1 Vector: AV:N/AC:H/AU:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1794299
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
