High priority
SAP security note 2023388, "Potential information disclosure relating to password", was released on February 10, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to passwords of PI service users. This information could be used to allow the attacker to specialize attacks against Process Integration.
Solution
This is fixed with the Support Packages and Patches attached to this SAP note.
Reason and prerequisites
Information such as the passwords can be discovered using the log viewer. This information may be used by an attacker to further target Process Integration.
Full note on SAP: SAP Support Launchpad note 2023388
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
