SAP Security Note
Medium priority
SAP security note 1677912, “Credit cards in order”, released on 12.11.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to credit cards. This information could be used to allow the attacker to specialize their attacks against credit cards and SD-BIL-IV-PC.
Solution
Implement the attached program corrections.
Reason and prerequisites
Information such as credit card holders and the validity of a credit card can be discovered using SD-BIL-IV-PC. This information may be used by an attacker to further target credit cards.
References
- 397329 – No message if expiration date of card is missing
- 827347 – No encryption after changing card number
Full note on SAP: SAP Support Launchpad note 1677912
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
