SAP security note 2653846, "[CVE-2018-2448] Information Disclosure in SRM MDM Catalog". Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions, the SRM MDM Utilities functionality allows an attacker to access information about user existence, which should otherwise be restricted.
An attacker can exploit this vulnerability by accessing the MDM Utilities functionality via the following URL:
http://<HOST>:<PORT>/webdynpro/resources/sap.com/tc~mdm~srmcat~uiutil/Utilities#
Solution
The solution is available in SAP NetWeaver Master Data Management 7.3 and above. Implement the support packages and patches referenced by this SAP Note.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2653846
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
