SAP Security Note
High priority
SAP security note 1565428, "Potential Information Disclosure of Server Information", is a program error note released on 12.07.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can discover information relating to server information. This information could be used to allow the malicious user to specialize their attacks against the server.
Solution
Apply the correction attached to the note. In case the coding does not exist in the system, nothing needs to be done.
Reason and prerequisites
Information such as profile parameters can be discovered using BC-UPG. This function exists only if an upgrade to basis release 700 or higher was performed.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
Affected components
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 730
- SAP_BASIS 72L to 800
Full note on SAP: SAP Support Launchpad note 1565428
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
