Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2448 Information Disclosure in SRM MDM Catalog, SAP security note 2653846

SAP Note 2653846

SAP security note 2653846, "[CVE-2018-2448] Information Disclosure in SRM MDM Catalog". Below are the symptom and SAP recommended solution.

Description

Symptom

Under certain conditions, the SRM MDM Utilities functionality allows an attacker to access information about user existence, which should otherwise be restricted.

An attacker can exploit this vulnerability by accessing the MDM Utilities functionality via the following URL:

http://<HOST>:<PORT>/webdynpro/resources/sap.com/tc~mdm~srmcat~uiutil/Utilities#

Solution

The solution is available in SAP NetWeaver Master Data Management 7.3 and above. Implement the support packages and patches referenced by this SAP Note.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2653846

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More