Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure in SAP NetWeaver Mobile Client, SAP security note 2528284

SAP Note 2528284

SAP security note 2528284, "Information Disclosure in SAP NetWeaver Mobile Client". Below are the symptom and SAP recommended solution.

Description

Symptom

The user logon credentials were encrypted and saved in a CRED file under the local directory of NetWeaver Mobile Client which could be reversed and manipulated.

Solution

Code changes have been implemented to use strong encryption via the Windows Certificate store, ensuring that CRED files are no longer stored in the Mobile Client folder. This resolves the information disclosure of customer logon credentials.

To apply the fix, please upgrade to at least the patch level mentioned in the "SP Patch Level" section of this note, as relevant to your release and service pack.

Reason and prerequisites

Reason: The encryption algorithm which was used to encrypt and store the logon credentials was weak and could be reversed.

Prerequisites: You are using NetWeaver Mobile Client:

  • 7.10 SP 21 or below
  • 7.11 SP 16 or below
  • 7.30 SP 04 or below

CVSS

Score 3.3 / 10 Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2528284

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More