SAP security note 2045668, “Potential information disclosure relating to XMLForms”, is a note released on 11.11.2014. Below is the security information published by SAP for this note.
Description
Symptom
An attacker can discover information relating to XMLForms. This information could be used to allow the attacker to specialize their attacks against XMLForms and AS Java.
Reason and prerequisites
Information such as runtime environment information can be discovered using XMLForms. This information may be used by an attacker to further target XMLForms and AS Java.
Solution
See the SP Patch Level section of this SAP Note for details. You can download the note in SNOTE format or view the PDF version:
- Download for SNOTE
- PDF Version
Affected components
- KMC-CM versions 7.00 to 7.40
References
- 2004850 – Central Note for KM&COLL for NW 701 SP17
- 2004848 – Central Note for KM&COLL for NW 700 SP32
- 2111044 – Central Note for NetWeaver 7.31 SP15 Enterprise Portal
- 2034444 – Central Note for KMC in the NW 7.31 SP14
Full note on SAP: SAP Support Launchpad note 2045668
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
