Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure in PI Axis Adapter, SAP security note 2745211

SAP Note 2745211

SAP security note 2745211, "Information Disclosure in PI Axis Adapter", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, the PI Axis Adapter allows an attacker to access information that would otherwise be restricted.

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The default servlet is now protected for HTTP-GET requests.

Reason and prerequisites

The default servlet does not require authentication for HTTP-GET methods.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected components

  • SAP_XIAF (versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50)

Full note on SAP: SAP Support Launchpad note 2745211

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More