Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure in SAP NetWeaver Instance Agent Service, SAP security note 2504129

SAP Note 2504129

SAP security note 2504129, "Information Disclosure in SAP NetWeaver Instance Agent Service". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, sapstartsrv allows an attacker to access information which would otherwise be restricted.

Impacts of Information Disclosure:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

Implement the corrected version of sapstartsrv as specified in this SAP Note. Ensure you are using at least the version and Patch Level mentioned in the note. As a temporary workaround, you can use service/protectedwebmethods=SDEFAULT +J2EEComponentList.

Reason and prerequisites

On AS Java instances, the Web method J2EEGetComponentList of sapstartsrv can be accessed without authentication even if authentication was enforced in the configuration (e.g., using service/protectedwebmethods=SDEFAULT, see SAP Note 927637 and SAP Note 1439348).

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected components

  • KRNL32NUC: 7.21, 7.21EXT, 7.22, 7.22EXT
  • KRNL32UC: 7.21, 7.21EXT, 7.22, 7.22EXT
  • KRNL64NUC: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.42, 7.45, 7.49, 7.50, 7.51, 7.52, 7.53
  • KRNL64UC: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.42, 7.45, 7.49, 7.50, 7.51, 7.52, 7.53
  • KERNEL: 7.21 to 7.22, 7.42, 7.45, 7.49, 7.50, 7.51, 7.52, 7.53

Full note on SAP: SAP Support Launchpad note 2504129

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More