Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential Disclosure of AS Java Related Information, SAP security note 1979543

SAP Note 1979543

SAP security note 1979543, “Potential Disclosure of AS Java Related Information”, is a note. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Security, User Management > Logon, SSO

Description

Symptom

An attacker can discover AS Java related information by using the AS Java’s logon application. This information could be used to specialize attacks against the AS Java and its logon application.

Solution

Update your AS Java to a Support Package or release where the issue is fixed. See the Support Package Patches section for details and available patches.

Reason and prerequisites

Information such as user passwords can be discovered when using the logon application. This information may be used by an attacker to further target the AS Java.

Full note on SAP: SAP Support Launchpad note 1979543

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More