SAP security note 2883638, “Information Disclosure in Supplier Relationship Management”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, the SRM Catalog allows an attacker to access information that would otherwise be restricted.
Some well-known impacts of Information Disclosure include:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
The affected system components no longer reveal sensitive information to users via the browser cache.
Reason and prerequisites
This is a program error.
The prerequisite for this vulnerability is that BYPASS_OUTB_HANDLER is not set to true in the Standard Call Structure configuration for the particular Catalog in SPRO.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Affected components
- SRM_SERVER versions 700 to 714
Full note on SAP: SAP Support Launchpad note 2883638
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
