SAP security note 2281002, "Information Disclosure in Portal Netweaver Client Services". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, EPCF allows an attacker to access information which would otherwise be restricted. This can lead to:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
EPCF no longer reveals internal information. To address this issue:
- Check the appropriate SP Patch Level within this note under the "SP Patch Level" tab.
- Apply the relevant support package patches as listed below.
Reason and prerequisites
Information such as product versions can be discovered using EPCF. An attacker may use this information to further target Portal Netweaver.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
- SAP Note 2270720 – Collective Note: SAP NetWeaver 7.30 SP16 – EP Core – Application Portal
- SAP Note 2237592 – Central Note for Portal Platform in SAP NW7.1 SP21
Affected components
- EP-PSERV (7.00 to 7.02)
- EP-RUNTIME (7.10 to 7.50)
- PORTAL (7.00 to 7.02)
Full note on SAP: SAP Support Launchpad note 2281002
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
