Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure in contact scenario, SAP security note 1779676

SAP Note 1779676

SAP security note 1779676, "Potential information disclosure in contact scenario". Below are the symptom and SAP recommended solution.

Description

Symptom

In a Web Channel Experience Management (WCEM) application based on the contact person scenario (B2B), an attacker can discover information relating to a sold-to party for which they have no access authorizations.

Solution

To resolve the issue, deploy the Java patch mentioned in this note from the SAP Service Marketplace or a higher version.

Reason and prerequisites

Information such as sales and service orders available about a sold-to party in a WCEM contact scenario application can be discovered using a contact scenario application of the WCEM.

CVSS

Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P

Full note on SAP: SAP Support Launchpad note 1779676

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More