Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure in Supplier Relationship Management, SAP security note 2883638

SAP Note 2883638

SAP security note 2883638, “Information Disclosure in Supplier Relationship Management”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Under certain conditions, the SRM Catalog allows an attacker to access information that would otherwise be restricted.

Some well-known impacts of Information Disclosure include:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The affected system components no longer reveal sensitive information to users via the browser cache.

Reason and prerequisites

This is a program error.

The prerequisite for this vulnerability is that BYPASS_OUTB_HANDLER is not set to true in the Standard Call Structure configuration for the particular Catalog in SPRO.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Affected components

  • SRM_SERVER versions 700 to 714

Full note on SAP: SAP Support Launchpad note 2883638

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More