SAP security note 2802521, "[CVE-2019-0356] Information Disclosure in XI Runtime Workbench of SAP NetWeaver Process Integration". Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions XI Runtime Workbench of SAP NetWeaver Process Integration allows an attacker to access information which would otherwise be restricted.
Some well-known impacts of Information Disclosure are:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
By applying the patch from the current note in XI Runtime Workbench of SAP NetWeaver Process Integration, the internal information (like debug traces) is restricted and cannot be accessed by malicious users.
The fix is provided with the Support Packages and Patches attached to this SAP note.
Reason and prerequisites
Some internal information like debug traces should not be visible to the end users. This information can potentially be used by a malicious user to further target the PI system.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2802521
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
