SAP security note 1779676, "Potential information disclosure in contact scenario". Below are the symptom and SAP recommended solution.
Description
Symptom
In a Web Channel Experience Management (WCEM) application based on the contact person scenario (B2B), an attacker can discover information relating to a sold-to party for which they have no access authorizations.
Solution
To resolve the issue, deploy the Java patch mentioned in this note from the SAP Service Marketplace or a higher version.
Reason and prerequisites
Information such as sales and service orders available about a sold-to party in a WCEM contact scenario application can be discovered using a contact scenario application of the WCEM.
CVSS
Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1779676
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
