SAP security note 2005351, “Potential information disclosure relating to SRM”, is a program error note released on June 11, 2014. Below is the security information published by SAP for this note.
Description
Overview
- SAP Note/KBA: 2005351
- Type: SAP Security Note
- Category: Program error
- Priority: Correction with high priority
- Status: Released for Customer
- Released On: June 11, 2014
- Component: Supplier Relationship Management > SRM > Cross-Application Functions > User Interface/Templates
Symptom
An attacker can discover information relating to Approval which uses SRM. This information could be used to allow the attacker to specialize their attacks against Approval and SRM.
Reason and prerequisites
Information can be disclosed using SRM. This information may be used by an attacker to further target Approval SRM.
Solution
Implement the attached correction instructions. Download Correction Instructions
Full note on SAP: SAP Support Launchpad note 2005351
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



