Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0356 Information Disclosure in XI Runtime Workbench of SAP NetWeaver Process Integration, SAP security note 2802521

SAP Note 2802521

SAP security note 2802521, "[CVE-2019-0356] Information Disclosure in XI Runtime Workbench of SAP NetWeaver Process Integration". Below are the symptom and SAP recommended solution.

Description

Symptom

Under certain conditions XI Runtime Workbench of SAP NetWeaver Process Integration allows an attacker to access information which would otherwise be restricted.

Some well-known impacts of Information Disclosure are:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

By applying the patch from the current note in XI Runtime Workbench of SAP NetWeaver Process Integration, the internal information (like debug traces) is restricted and cannot be accessed by malicious users.

The fix is provided with the Support Packages and Patches attached to this SAP note.

Reason and prerequisites

Some internal information like debug traces should not be visible to the end users. This information can potentially be used by a malicious user to further target the PI system.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2802521

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More