Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0380 Information Disclosure vulnerability in SAP Landscape Management Enterprise, SAP security note 2828682

SAP Note 2828682

SAP security note 2828682, "Information Disclosure vulnerability in SAP Landscape Management Enterprise". Below are the symptom and SAP recommended solution.

ComponentBasis Components > Virtualization / Cloud Management > Landscape Virtualization Management (BC-VCM-LVM)

Description

Symptom

Under certain conditions, SAP Landscape Management Enterprise Edition allows access to information that should otherwise be restricted. Specifically, custom parameters with the security flag checked may be disclosed. Although this vulnerability is classified as Hot News, the attack requires specific and uncommon conditions. However, the exposed information can be critical.

Solution

  1. Apply Patch: Implement SAP Landscape Management 3.0 SP12 Patch02. SAP Note 2843868
  2. Manual Correction Instructions: Perform the manual correction instructions described in this SAP Note. Execute at least Goal 1 from the Manual Correction Instructions to enable the fix delivered with the referenced patch.

CVSS

Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2828682

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More