Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to SBOP Explorer, SAP security note 1908562

SAP Note 1908562
SAP Security Note
High priority

SAP security note 1908562, "Potential information disclosure relating to SBOP Explorer", is a program error note released on 10.12.2013. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Reporting, analysis, and dashboards > Obsolete: Polestar, Explorer
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on10.12.2013
LanguageEnglish

Description

Symptom

An attacker can discover information relating to the CMS port used for SBOP BI PLATFORM. This information could be used to allow the attacker to specialize their attacks against the CMS and SBOP BI PLATFORM.

Solution

The solution is included in:

  • 4.0 SP7 Patch1 and later
  • 4.0 SP8
  • 4.1 SP1 Patch1 and later
  • 4.1 SP2

Additionally, you can edit the default.settings file (located in the WEB-INF\classes folder of the SBOP Explorer webapp) and set:

  • show.cms.name=false
  • disable.cms.name=true

By default, the value of disable.cms.name will be true after the fix. All logins will use the default.cms.name setting from the file even if it is changed in the XML sent to SBOP Explorer.

Reason and prerequisites

Information such as the landscape configuration can be discovered using SBOP Explorer. This information may be used by an attacker to further target the CMS of the SBOP BI PLATFORM.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 1908562

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More