SAP security note 1440345, "Load balancer reveals backend server information", is a special development note released on 14.09.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A load balancer reveals backend server information by exposing the server instance IDs as part of session information.
Solution
Install the patch levels specified in this note at a minimum.
Reason and prerequisites
The server instance information is irrelevant in this context and can be removed to restrict system information to the necessary minimum. This information leak was only observed and reproducible with NetWeaver versions 7.10 and 7.11.
References
- 1495500 – Dependency between Java Engine and native kernel in 7.1x/720
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SAP_BASIS 7.10 to 7.11
Full note on SAP: SAP Support Launchpad note 1440345
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



