SAP security note 2601492, "[CVE-2018-2417] Information Disclosure in SAP Identity Management Runtime component", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, the SAP Identity Management "ToASCII" pass allows an attacker to access information which would otherwise be restricted.
Impacts:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
Apply the attached patch provided in the Support Packages & Patches section of this SAP Note.
Make sure all components are updated to the corresponding SP level before applying the patch.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
- CVE-2018-2417
Affected components
- Identity Management Runtime component (BC-IAM-IDM)
Full note on SAP: SAP Support Launchpad note 2601492
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
