Medium priority
SAP security note 2793351, "[CVE-2019-0338] Information Disclosure in SAP Gateway", is a note released on August 13, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, SAP Gateway allows an attacker to access information that should otherwise be restricted.
Impacts:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
The HTTP response headers are now correctly considered while processing an OData V2/V4 request.
Reason and prerequisites
The HTTP protocol allows determination of whether the transmitted responses of the Web server may be cached using the cache-control and pragma headers. During an OData V2/V4 request, these HTTP headers were not properly set, leading to potential information disclosure.
CVSS
Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
- CVE Details
Affected components
- SAP_GWFND (Gateway Framework) – versions 750, 751, 752, 753
Full note on SAP: SAP Support Launchpad note 2793351
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
