SAP Security Note
High priority
SAP security note 1908562, "Potential information disclosure relating to SBOP Explorer", is a program error note released on 10.12.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to the CMS port used for SBOP BI PLATFORM. This information could be used to allow the attacker to specialize their attacks against the CMS and SBOP BI PLATFORM.
Solution
The solution is included in:
- 4.0 SP7 Patch1 and later
- 4.0 SP8
- 4.1 SP1 Patch1 and later
- 4.1 SP2
Additionally, you can edit the default.settings file (located in the WEB-INF\classes folder of the SBOP Explorer webapp) and set:
- show.cms.name=false
- disable.cms.name=true
By default, the value of disable.cms.name will be true after the fix. All logins will use the default.cms.name setting from the file even if it is changed in the XML sent to SBOP Explorer.
Reason and prerequisites
Information such as the landscape configuration can be discovered using SBOP Explorer. This information may be used by an attacker to further target the CMS of the SBOP BI PLATFORM.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1908562
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
