Medium priority
SAP security note 2307947, “Information Disclosure in Runtime Workbench”, is a note released on August 9, 2016. Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions, the PI Runtime Workbench allows an attacker to access information that would otherwise be restricted. This vulnerability can lead to:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
This issue is resolved with the Support Packages and Patches referenced in this SAP Note. Ensure that you apply the relevant updates to mitigate the risk of information disclosure.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2307947
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
