SAP security note 2504129, "Information Disclosure in SAP NetWeaver Instance Agent Service". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, sapstartsrv allows an attacker to access information which would otherwise be restricted.
Impacts of Information Disclosure:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
Implement the corrected version of sapstartsrv as specified in this SAP Note. Ensure you are using at least the version and Patch Level mentioned in the note. As a temporary workaround, you can use service/protectedwebmethods=SDEFAULT +J2EEComponentList.
Reason and prerequisites
On AS Java instances, the Web method J2EEGetComponentList of sapstartsrv can be accessed without authentication even if authentication was enforced in the configuration (e.g., using service/protectedwebmethods=SDEFAULT, see SAP Note 927637 and SAP Note 1439348).
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected components
- KRNL32NUC: 7.21, 7.21EXT, 7.22, 7.22EXT
- KRNL32UC: 7.21, 7.21EXT, 7.22, 7.22EXT
- KRNL64NUC: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.42, 7.45, 7.49, 7.50, 7.51, 7.52, 7.53
- KRNL64UC: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.42, 7.45, 7.49, 7.50, 7.51, 7.52, 7.53
- KERNEL: 7.21 to 7.22, 7.42, 7.45, 7.49, 7.50, 7.51, 7.52, 7.53
Full note on SAP: SAP Support Launchpad note 2504129
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



