Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to NavigationServlet, SAP security note 2193424

SAP Note 2193424SAP Security NoteMedium priority

SAP security note 2193424, “Potential information disclosure relating to NavigationServlet”, is released on January 12, 2016. Below are the symptom, SAP recommended solution and the affected software components.

PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released onJanuary 12, 2016

Description

Symptom

An attacker can discover information related to NavigationServlet. This information could be leveraged to specialize attacks targeting NavigationServlet, potentially compromising system integrity.

Solution

Apply the appropriate support package patches to address this vulnerability. Refer to the Support Package Patches for detailed information on available fixes.

CVSS

Score 5.0 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

References

Affected components

  • EP-RUNTIME 7.30, 7.31, 7.40, 7.50

Full note on SAP: SAP Support Launchpad note 2193424

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More