Medium priority
SAP security note 2536422, "Information Disclosure in Customer factsheet", is a note released on 27.02.2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
When navigating from the enterprise search result page to the customer factsheet, an attacker can access information that is otherwise restricted. This information disclosure can lead to:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
Implement the correction provided in the note and follow the post-implementation steps outlined below.
Affected components
- S4CORE 100
- S4CORE 101
- S4CORE 102
Full note on SAP: SAP Support Launchpad note 2536422
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
