SAP security note 2180403, "Potential information disclosure relating to ABAP Debugger." Below are the symptom and the SAP recommended solution.
Description
Symptom
An attacker can discover information relating to SAP internal and technical components using the ABAP Debugger. This information could be used to allow the attacker to specialize their attacks against SAP application server ABAP.
Solution
Please implement the kernel patch level mentioned in this SAP Note.
Reason and prerequisites
Information such as user passwords can be discovered using the ABAP Debugger. This information may be used by an attacker to further target the SAP application server ABAP.
Full note on SAP: SAP Support Launchpad note 2180403
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
