SAP Security Note
High priority
SAP security note 1591438, “Disclosing information about table contents in IS-M/SD”, is a program error note released on 14.06.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can obtain information regarding sensitive billing data. This information could be used to allow the malicious user to specialize their attacks against the contents of these tables.
Solution
Import the relevant Support Package or implement the attached advance correction.
Reason and prerequisites
Information such as sensitive billing data can be discovered by using IS-M/SD. This information can then be used to retrieve data from the database.
CVSS
Score 0
References
This note refers to
Affected components
- IS-M 600
- IS-M 602
- IS-M 603
- IS-M 604
- IS-M 605
Full note on SAP: SAP Support Launchpad note 1591438
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
