SAP Security Note
Medium priority
SAP security note 2445033, "Information Disclosure in SAP NetWeaver Message Server", is a program error note released on 13.06.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, the SAP NetWeaver Message Server allows an attacker to access information that would otherwise be restricted. This can lead to:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
Access to configuration values via SAP Message Server administration messages is restricted by the correction provided in this note.
Reason and prerequisites
An attacker could exploit specially crafted administration messages to retrieve configuration information of the SAP Message Server.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
Referenced by
- SAP Note 2626837 – ‘isUnicode’: Radio group contains an invalid value ”. Valid values are: false|true|
Affected components
- KRNL32NUC (7.21, 7.21EXT)
- KRNL32UC (7.21, 7.21EXT)
- KRNL64NUC (7.21, 7.21EXT, 7.22, 7.22EXT, 7.49)
- KRNL64UC (7.21, 7.21EXT, 7.22, 7.22EXT, 7.49)
- KERNEL (7.21 to 7.22, 7.45, 7.49)
Full note on SAP: SAP Support Launchpad note 2445033
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




