High priority
SAP security note 1894049, "Potential information disclosure relating to SLM", was released on January 14, 2014. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker could make an HTTP GET request to certain URLs provided by the Software Lifecycle Manager (SLM) to obtain sensitive information that can be used to perform more sophisticated attacks.
This vulnerability allows for potential information disclosure, which might aid attackers in building more targeted attacks against your systems.
Solution
Apply the appropriate patch for the SWLIFECYCL component. The required Support Package levels are:
- NW701 SP11 or later
- NW702 SP11 or later
- NW710 SP14 or later
- NW711 SP9 or later
- NW720 SP5 or later
- NW730 SP7 or later
- NW731 SP6 or later
Reason and prerequisites
The issue arises from some JSP pages developed for testing JNET technology that were not removed before the application was delivered to customers.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1894049
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
