SAP Security Note
High priority
SAP security note 1679897, “PI SEC: Potential information disclosure in PI AF”, is released on 13.11.2012. Below are the symptom, SAP recommended solution, CVSS score, references and the affected software components.
Description
Symptom
An attacker can discover information relating to ‘PI Adapter Framework’. This information could be used to allow the attacker to specialize their attacks against ‘PI Adapter Framework’.
Solution
This issue is fixed with the Support Packages and Patches of Software Component ‘XI ADAPTER FRAMEWORK’ (SAPXIAF) referenced by this note in the section ‘SP Patch Level’.
Reason and prerequisites
Information such as the ‘Communication Components’ names can be discovered using PI Adapter Framework. This information may be used by an attacker to further target.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
- SAP EhP2 for Netweaver 7.00 SP13
- SAP EhP1 for XI on Netweaver 7.00 SP13
- NW04s XI Support Package Stack 28
- SAP EhP2 for Netweaver 7.00 SP12
- SAP EhP1 for XI on Netweaver 7.00 SP12
- SAP Netweaver for PI 7.10 Support Package 15
- SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP10
- NW04s XI Support Package Stack 27
- XI 30 Support Package Stack (SPS) 30
Affected components
- SAP_XIAF versions 3.0, 7.00 to 7.31
Full note on SAP: SAP Support Launchpad note 1679897
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
