SAP Security Note
High priority
SAP security note 1420623, "MOpz: Potential information disclosure relating to passwords", is a program error note released on 08.03.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can discover information relating to passwords when using Maintenance Optimizer (MOpz) with Software Lifecycle Manager (SLM). This information could be exploited to target passwords and systems managed by SLM more effectively.
Solution
Implement the attached correction instructions to mitigate this risk. You can download the correction instructions using the link below.
Reason and prerequisites
Information such as user passwords can be discovered using MOpz. This could be leveraged by a malicious user to further target passwords.
Full note on SAP: SAP Support Launchpad note 1420623
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



