Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to SAPCCMS, SAP security note 2091768

SAP Note 2091768
SAP Security Note
High priority

SAP security note 2091768, "Potential information disclosure relating to SAPCCMS", is a program error note released on 10.03.2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Computer Center Management System (CCMS) > CCMS Monitoring & Alerting
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on10.03.2015
LanguageEnglish

Description

Symptom

An attacker can discover the value of SAP profile parameters via the SAPCCMS WS call ReadProfileParameters.

Solution

Upgrade your kernel to the associated patch level.

Reason and prerequisites

Values of SAP profile parameters can be discovered using the web-service SAPCCMS. This information may be further used by an attacker.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2091768

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More