SAP Security Note
Medium priority
SAP security note 2944988, "[CVE-2020-6310] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform", is a program error note released on 11.08.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
Improper access control in the SOA Configuration Trace component in SAP NetWeaver ABAP Server and ABAP Platform allows an authenticated user to access user details, such as usernames, leading to information disclosure.
Solution
The value help for the user list is removed from SOA Configuration Trace. Please implement the correction by applying the correction instruction or update to the support package mentioned in this SAP Note.
Reason and prerequisites
SOA Configuration Trace allows a business user to access the list of users in the given system using value help (F4 help). The access to the list is not restricted.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2944988
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



