SAP security note 1899146, "Potential disclosure of information about PI", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information related to PI that is used during the PI runtime. This information could be used to allow the attacker to specialize their attacks against PI and the Adapter Framework.
Solution
Implement the correction instructions or import the relevant Support Package.
Reason and prerequisites
Information such as user passwords can be disclosed using PI. This information may be used by an attacker to further target PI.
Full note on SAP: SAP Support Launchpad note 1899146
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
