SAP security note 2528284, "Information Disclosure in SAP NetWeaver Mobile Client". Below are the symptom and SAP recommended solution.
Description
Symptom
The user logon credentials were encrypted and saved in a CRED file under the local directory of NetWeaver Mobile Client which could be reversed and manipulated.
Solution
Code changes have been implemented to use strong encryption via the Windows Certificate store, ensuring that CRED files are no longer stored in the Mobile Client folder. This resolves the information disclosure of customer logon credentials.
To apply the fix, please upgrade to at least the patch level mentioned in the "SP Patch Level" section of this note, as relevant to your release and service pack.
Reason and prerequisites
Reason: The encryption algorithm which was used to encrypt and store the logon credentials was weak and could be reversed.
Prerequisites: You are using NetWeaver Mobile Client:
- 7.10 SP 21 or below
- 7.11 SP 16 or below
- 7.30 SP 04 or below
CVSS
Score 3.3 / 10 Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2528284
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
