Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to Internet Communication Framework, SAP security note 2157458

SAP Note 2157458SAP Security NoteMedium priority

SAP security note 2157458, "Potential Information Disclosure in Internet Communication Framework", is released on August 11, 2015. Below are the symptom and the SAP recommended solution.

ComponentInternet Communication Framework (BC-MID-ICF)
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released onAugust 11, 2015

Description

Symptom

An attacker can discover information related to HTTP request header attributes. This information could be utilized to tailor attacks against SAP applications.

Solution

The correction in the Internet Communication Framework removes sensitive information before the HTTP request is passed to the application. To mitigate this vulnerability:

Reason and prerequisites

This note is applicable if you have implemented SAP Note 1559556, which addresses visible security session ID cookies in HTTP requests.

CVSS

Score 4.3 / 10 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2157458

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More