Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to SADL Runtime, SAP security note 2156031

SAP Note 2156031
High priority

SAP security note 2156031, "Potential information disclosure relating to SADL Runtime", is a note released on 09.06.2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Enterprise Service Infrastructure > Enterprise Service Framework Layer > Business Service Adaptation
PriorityHigh priority
Released on09.06.2015

Description

Symptom

An attacker can discover information relating to business data by SADL Runtime. This information could be used to allow the attacker to specialize their attacks against persons or business and AS ABAP.

Information such as business data stored in SAP can be discovered using SADL Runtime. This information may be used by an attacker to further target persons, systems, and applications.

Solution

Please apply the Support Package SAP NetWeaver 740 SP12, or the correction instructions for SAP NetWeaver 740 SP10 and SP11.

Full note on SAP: SAP Support Launchpad note 2156031

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More