Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure in Portal Netweaver Client Services, SAP security note 2281002

SAP Note 2281002

SAP security note 2281002, "Information Disclosure in Portal Netweaver Client Services". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, EPCF allows an attacker to access information which would otherwise be restricted. This can lead to:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

EPCF no longer reveals internal information. To address this issue:

  • Check the appropriate SP Patch Level within this note under the "SP Patch Level" tab.
  • Apply the relevant support package patches as listed below.

Reason and prerequisites

Information such as product versions can be discovered using EPCF. An attacker may use this information to further target Portal Netweaver.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

Affected components

  • EP-PSERV (7.00 to 7.02)
  • EP-RUNTIME (7.10 to 7.50)
  • PORTAL (7.00 to 7.02)

Full note on SAP: SAP Support Launchpad note 2281002

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More