SAP Security Note
SAP security note 1916560, “Potential information disclosure relating to bidders”, is a note released on 14.01.2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to bidders who use SRM Live Auction (SRM-LA). This information could be used to allow the attacker to specialize their attacks against other bidders and SRM-LA.
Solution
Please implement this note for this fix.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
Affected components
- SRM_SERVER versions 500, 550, 600, 700, 701, 702, 713
Full note on SAP: SAP Support Launchpad note 1916560
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



