Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0248 Information Disclosure in SAP Gateway of ABAP Application Server, SAP security note 2723142

SAP Note 2723142

SAP security note 2723142, "[CVE-2019-0248] Information Disclosure in SAP Gateway of ABAP Application Server", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

Under certain conditions, the SAP Gateway of the ABAP Application Server allows an attacker to access information that should otherwise be restricted. This information disclosure can lead to:

Loss of information and system configuration confidentiality.

Information gathering for further exploits and attacks.

SAP Gateway exposes lower layer error information to upper layers or even business users, potentially leading to confidential information being accessible to unauthorized parties.

Solution

Apply the relevant Support Package provided in this SAP Note or follow the respective correction instructions to prevent SAP Gateway from exposing technical layer error information to interfaces and business users.

CVSS

Score 4.3 Vector: CVSS:/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2723142

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More