Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information Disclosure vulnerability in LDAP Authentication for SAP BusinessObjects Enterprise, SAP security note 2458021

SAP Note 2458021
Medium priority

SAP security note 2458021, "Information Disclosure vulnerability in LDAP Authentication for SAP BusinessObjects Enterprise", is a note released on October 10, 2017. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Business intelligence platform > Authentication, ActiveDirectory, LDAP, SSO, Vintela
PriorityCorrection with medium priority
StatusReleased for Customer
Released onOctober 10, 2017

Description

Symptom

LDAP Authentication in SAP BusinessObjects Enterprise was allowing unauthorized users to gain information about the underlying LDAP system. Information Disclosure can aid attackers in creating further attacks on a customer system.

Solution

The fix makes the product no longer display unnecessary details when LDAP Authentication fails.

CVSS

Score 5.3/10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2458021

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More