SAP security note 2048335, “Potential information disclosure relating to KM Content”. Below are the symptom and SAP recommended solution.
Description
Symptom
Possible revealing of information related to KM Content in SAP NW Enterprise Portal (EP). This information could be used for specialized attacks against Knowledge Management, EP, and AS JAVA.
Solution
Refer to the Support Package Patches section for details on the necessary patches to mitigate this issue.
Reason and prerequisites
Information such as runtime environment details can be discovered using KM Content. This information may be leveraged by an attacker to further target Knowledge Management, EP, and AS JAVA.
CVSS
Score 4.0 / 10 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2048335
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




