SAP Security Note
High priority
SAP security note 1558740, “Potential information disclosure relating server information”, is a program error note released on 12.04.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can discover information relating to the names of server data files being used, for example, to deliver landscape configuration data. This information could be used to allow the malicious user to specialize their attacks against relating server information and IS Migration Workbench.
Solution
Implement the corrections in accordance with the correction instructions, or import the relevant Support Package.
Reason and prerequisites
Information such as the names of data files in the SAP file system can be discovered using function modules of the IS Migration Workbench. This information may be used by a malicious user to further target landscape configuration data.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Affected components
- IS-U/CCS: Versions 461, 464, 471
- FI-CA: Versions 472, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1558740
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
