Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to logon information, SAP security note 1922154

SAP Note 1922154

SAP security note 1922154, "Potential information disclosure relating to logon information", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can discover logon information in BPC NW. This information could be used to allow the attacker to specialize their attacks against BPC.

Solution

Please update your BPC .Net Server to SP16 Patch02 or a later SP.

Reason and prerequisites

This is caused by a program error. It is only relevant for BPC NW release 7.5. Information disclosure may happen when you log on to BPC Web if you’re using SAP CMS authentication.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 1922154

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More