SAP security note 1922154, "Potential information disclosure relating to logon information", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover logon information in BPC NW. This information could be used to allow the attacker to specialize their attacks against BPC.
Solution
Please update your BPC .Net Server to SP16 Patch02 or a later SP.
Reason and prerequisites
This is caused by a program error. It is only relevant for BPC NW release 7.5. Information disclosure may happen when you log on to BPC Web if you’re using SAP CMS authentication.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 1922154
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
