SAP security note 2055411, "Potential information disclosure relating to E-Commerce/Web Channel". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information related to E-Commerce/Web Channel using CRM-ISA-TEC. This information could be leveraged to tailor attacks specifically against E-Commerce/Web Channel and CRM-ISA-TEC.
Solution
This note includes Java Corrections for E-Commerce/Web Channel. To address the issue, implement the Support Package (SP) Patch Level attached to this note.
For detailed instructions on installing Java Patches, refer to:
- Installing Patches for CRM Java Components and FSCM BD
- Patch Strategies for SAP E-Commerce solutions
CVSS
Score 5.0 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected components
- Customer Relationship Management > Internet Sales > Technical Infrastructure (CRM-ISA-TEC)
Full note on SAP: SAP Support Launchpad note 2055411
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



