SAP security note 1997455, "Potential information disclosure in BC-SEC-USR-ADM", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information of all SAP central CUA system tables.
Solution
Implement the relevant Support Package.
Alternatives:
- Maintain role and adjust authorization: keep your active copy of the role SAP_BC_USR_CUA_CENTRAL, and delete ‘SDTX’ as a function group from the authorization object S_RFC.
- Update role via attachment: a new version of the role SAP_BC_USR_CUA_CENTRAL is available as a file attachment. Upload the attachment SAP_BC_USR_CUA_CENTRAL.TXT dated 27th March 2014 into your affected systems. This update is applicable for all SAP_BASIS releases from version 7.00 onwards.
Reason and prerequisites
Only systems that currently use the Central User Administration (CUA) central system and have not adopted the proposals delivered in the role SAP_BC_USR_CUA_CENTRAL to your active role are affected. Information such as table content can be discovered.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1997455
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



