SAP security note 1852146, "Potential information disclosure relating to the Portal", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to a server that uses Lightspeed. This information could be used to allow the attacker to specialize their attacks against Enterprise Portals.
Solution
Please apply the current Support Package/Patch.
Reason and prerequisites
Information such as the landscape configuration can be discovered using special pages. This information may be used by an attacker to further target NetWeaver systems.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Affected components
- AJAX-RUNTIME 7.20
- AJAX-RUNTIME 7.30
- AJAX-RUNTIME 7.31
- AJAX-RUNTIME 7.40
- FRAMEWORK 7.11
Full note on SAP: SAP Support Launchpad note 1852146
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



