Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

MOpz Potential information disclosure relating to passwords, SAP security note 1420623

SAP Note 1420623
SAP Security Note
High priority

SAP security note 1420623, "MOpz: Potential information disclosure relating to passwords", is a program error note released on 08.03.2011. Below are the symptom and SAP recommended solution.

ComponentService > SAP Solution Manager > Maint. Optimizer replaced by Maintenance Planner: BC-UPG-MP (SV-SMG-MAI)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on08.03.2011
LanguageEnglish

Description

Symptom

A malicious user can discover information relating to passwords when using Maintenance Optimizer (MOpz) with Software Lifecycle Manager (SLM). This information could be exploited to target passwords and systems managed by SLM more effectively.

Solution

Implement the attached correction instructions to mitigate this risk. You can download the correction instructions using the link below.

Reason and prerequisites

Information such as user passwords can be discovered using MOpz. This could be leveraged by a malicious user to further target passwords.

Full note on SAP: SAP Support Launchpad note 1420623

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More