SAP security note 2030775, “Missing Authentication Check In Utilities Application Included In The SRM-MDM Catalog”, is a note released on September 9, 2014. Below is the security information published by SAP for this note.
Description
An unauthenticated user can exploit the Utilities Application included in the SRM-MDM Catalog (SRM-CAT-MDM) to scan internal networks and retrieve information about open ports. This vulnerability may lead to unauthorized network reconnaissance and potential security breaches.
Affected components
- Component: Supplier Relationship Management > Catalogs > MDM Catalog (SRM-CAT-MDM)
- Versions Affected:
- 3.0
- 7.01
- 7.02
- 3.73
- 7.31
- 7.32
Solution
To mitigate this vulnerability, apply the latest patch for the SRM-MDM Catalog. You can download the patch using the following links:
- Download for SNOTE
- PDF Version
Additional information
- Released On: September 9, 2014
- Priority: Correction with High Priority
- Status: Released for Customer
Full note on SAP: SAP Support Launchpad note 2030775
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
