Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0338Information Disclosure in SAP Gateway, SAP security note 2793351

SAP Note 2793351
Medium priority

SAP security note 2793351, "[CVE-2019-0338] Information Disclosure in SAP Gateway", is a note released on August 13, 2019. Below are the symptom, SAP recommended solution and the affected software components.

PriorityMedium priority
StatusReleased for Customer
Released onAugust 13, 2019

Description

Symptom

Under certain conditions, SAP Gateway allows an attacker to access information that should otherwise be restricted.

Impacts:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The HTTP response headers are now correctly considered while processing an OData V2/V4 request.

Reason and prerequisites

The HTTP protocol allows determination of whether the transmitted responses of the Web server may be cached using the cache-control and pragma headers. During an OData V2/V4 request, these HTTP headers were not properly set, leading to potential information disclosure.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

  • CVE Details

Affected components

  • SAP_GWFND (Gateway Framework) – versions 750, 751, 752, 753

Full note on SAP: SAP Support Launchpad note 2793351

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More