Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure in SAP NetWeaver Message Server, SAP security note 2445033

SAP Note 2445033
SAP Security Note
Medium priority

SAP security note 2445033, "Information Disclosure in SAP NetWeaver Message Server", is a program error note released on 13.06.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology > Message Service
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on13.06.2017
LanguageEnglish

Description

Symptom

Under certain conditions, the SAP NetWeaver Message Server allows an attacker to access information that would otherwise be restricted. This can lead to:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

Access to configuration values via SAP Message Server administration messages is restricted by the correction provided in this note.

Reason and prerequisites

An attacker could exploit specially crafted administration messages to retrieve configuration information of the SAP Message Server.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

Referenced by

  • SAP Note 2626837 – ‘isUnicode’: Radio group contains an invalid value ”. Valid values are: false|true|

Affected components

  • KRNL32NUC (7.21, 7.21EXT)
  • KRNL32UC (7.21, 7.21EXT)
  • KRNL64NUC (7.21, 7.21EXT, 7.22, 7.22EXT, 7.49)
  • KRNL64UC (7.21, 7.21EXT, 7.22, 7.22EXT, 7.49)
  • KERNEL (7.21 to 7.22, 7.45, 7.49)

Full note on SAP: SAP Support Launchpad note 2445033

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More