Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to Explorer web application server, SAP security note 2260895

SAP Note 2260895

SAP security note 2260895, “Potential information disclosure relating to Explorer web application server”. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can discover information related to the SAP BusinessObjects Explorer web application server. This information could be used to tailor attacks specifically against the Explorer web application server.

Solution

The issue has been fixed in the patches listed in the "Support Package Patches" section below.

Information about web server specifications (web server type, version, etc.) and the Java environment has been removed from the config.jsp page (http://xxx/explorer/config.jsp). For Business Intelligence Platform maintenance schedule and strategy, see SAP Note 2144559 in the References section.

Reason and prerequisites

An attacker can discover information relating to the SAP BusinessObjects Explorer web application server. This information could enable the attacker to specialize their attacks against the Explorer web application server.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2260895

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More