High priority
SAP security note 2156031, "Potential information disclosure relating to SADL Runtime", is a note released on 09.06.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to business data by SADL Runtime. This information could be used to allow the attacker to specialize their attacks against persons or business and AS ABAP.
Information such as business data stored in SAP can be discovered using SADL Runtime. This information may be used by an attacker to further target persons, systems, and applications.
Solution
Please apply the Support Package SAP NetWeaver 740 SP12, or the correction instructions for SAP NetWeaver 740 SP10 and SP11.
Full note on SAP: SAP Support Launchpad note 2156031
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



