Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Information disclosure vulnerability in SAP NetWeaver Mobile Client, SAP security note 2510269

SAP Note 2510269

SAP security note 2510269, "Information disclosure vulnerability in SAP NetWeaver Mobile Client". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Truststore key file was getting saved in the local directory of NetWeaver Mobile Client, which could be decrypted and used for manipulating the Custom Certificates.

Solution

Code changes have been made to adapt to a more secure encryption method. The truststore master key is no longer stored in the local directory of SAP NetWeaver Mobile Client.

Fix is available from 7.11 SP15 Patch 01 onwards.

Upgrade the client to the above version or higher.

Reason and prerequisites

Truststore key file was getting saved under the local directory of the NetWeaver Mobile client folder.

You are using NetWeaver Mobile Client 7.11 SP16 Patch 00 or below.

CVSS

Score 3.8 Vector: AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

References

Affected components

  • NWMCLIENTSETUP: Versions from 7.11 to 7.11

Full note on SAP: SAP Support Launchpad note 2510269

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More