Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to SRM-EBP-CAT, SAP security note 2017651

SAP Note 2017651
SAP Security Note
High priority

SAP security note 2017651, "Potential information disclosure relating to SRM-EBP-CAT", is a program error note released on 15.01.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSupplier Relationship Management > Catalogs > MDM Catalog
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on15.01.2016
LanguageEnglish

Description

Symptom

An attacker can discover information relating to SRM-MDM Catalog in SRM-EBP-CAT. This information could be used to allow the attacker to specialize their attacks against SRM-MDM Catalog.

Solution

Implement the correction instructions provided.

Reason and prerequisites

Information such as user passwords can be discovered using a Shoulder Surfer attack. This information may be used by an attacker to further target SRM-MDM Catalog.

CVSS

Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N

References

Affected components

  • SRM_SERVER 550
  • SRM_SERVER 700
  • SRM_SERVER 701
  • SRM_SERVER 702
  • SRM_SERVER 713

Full note on SAP: SAP Support Launchpad note 2017651

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More