SAP security note 1661781, "Potential information disclosure relating to SRM-MDM". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to SRM-MDM Catalog. This information could be used to allow the attacker to specialize their attacks against SRM-MDM Catalog.
Solution
The solution will be available from:
- Catalog 7.01 SP07 Patch01 onwards for Catalog 7.01
- Catalog 3.0 SP11 Patch06 onwards for Catalog 3.0
- Catalog 7.01 SP00 Patch10 onwards for Catalog 7.01 NW7.3
- Catalog 3.0 SP00 Patch04 onwards for Catalog 3.0 NW7.3
Reason and prerequisites
Information such as the Item details can be discovered using SRM-MDM Catalog. This information may be used by an attacker to further target SRM.
CVSS
Score 5.8 Vector: AV:N/AC:M/AU:N/C:P/I:P/A:N
References
- SRM-MDM Catalog 7.0 EHP1 SP00 Patch10 on NW7.3 Release Note
- SRM-MDM Catalog 3.0 SP00 Patch 4 on NW7.3 Release Note
- Potential information disclosure relating to SRM-MDM Catalog
Affected components
- SRM_MDM_CAT: 3.0 to 3.0
- SRM_MDM_CAT: 7.01 to 7.01
- SRM_MDM_CAT: 3.73 to 3.73
- SRM_MDM_CAT: 7.31 to 7.31
Full note on SAP: SAP Support Launchpad note 1661781
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




