Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6310 Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform, SAP security note 2944988

SAP Note 2944988
SAP Security Note
Medium priority

SAP security note 2944988, "[CVE-2020-6310] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform", is a program error note released on 11.08.2020. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Enterprise Service Infrastructure > Web Service Infrastructure > Web Service and SOAP – ABAP > WebServices ABAP Configuration
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on11.08.2020
LanguageEnglish

Description

Symptom

Improper access control in the SOA Configuration Trace component in SAP NetWeaver ABAP Server and ABAP Platform allows an authenticated user to access user details, such as usernames, leading to information disclosure.

Solution

The value help for the user list is removed from SOA Configuration Trace. Please implement the correction by applying the correction instruction or update to the support package mentioned in this SAP Note.

Reason and prerequisites

SOA Configuration Trace allows a business user to access the list of users in the given system using value help (F4 help). The access to the list is not restricted.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2944988

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More