SAP security note 2446435, "Information Disclosure in FS-QUO". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, FS-QUO allows an attacker to access information which would otherwise be restricted.
Some well-known impacts of Information Disclosure are:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
With this fix, the application no longer reveals internal information when these error conditions occur. To apply this fix, implement the Support Package referenced by this SAP Note. There is no impact on application functionality other than the information provided under certain error conditions.
Reason and prerequisites
Under certain error conditions, FS-QUO could reveal details of the Java call stack and SQL statements.
Affected components
- FS-QUO 7.5
- FS-QUO 7.6
Full note on SAP: SAP Support Launchpad note 2446435
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




