Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to password, SAP security note 2023388

SAP Note 2023388
High priority

SAP security note 2023388, "Potential information disclosure relating to password", was released on February 10, 2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Process Integration (PI) > Connectivity > J2EE Adapter Framework > Directory Cache
PriorityCorrection with high priority
Released onFebruary 10, 2015

Description

Symptom

An attacker can discover information relating to passwords of PI service users. This information could be used to allow the attacker to specialize attacks against Process Integration.

Solution

This is fixed with the Support Packages and Patches attached to this SAP note.

Reason and prerequisites

Information such as the passwords can be discovered using the log viewer. This information may be used by an attacker to further target Process Integration.

Full note on SAP: SAP Support Launchpad note 2023388

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More