SAP security note 2828682, "Information Disclosure vulnerability in SAP Landscape Management Enterprise". Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions, SAP Landscape Management Enterprise Edition allows access to information that should otherwise be restricted. Specifically, custom parameters with the security flag checked may be disclosed. Although this vulnerability is classified as Hot News, the attack requires specific and uncommon conditions. However, the exposed information can be critical.
Solution
- Apply Patch: Implement SAP Landscape Management 3.0 SP12 Patch02. SAP Note 2843868
- Manual Correction Instructions: Perform the manual correction instructions described in this SAP Note. Execute at least Goal 1 from the Manual Correction Instructions to enable the fix delivered with the referenced patch.
CVSS
Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
References
- SAP Landscape Management 3.0 SP12 Patch02
- SAP Landscape Management – Collective Security Note 2910170
Full note on SAP: SAP Support Launchpad note 2828682
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
