SAP Security Note
SAP security note 1715040, “Potential information disclosure relating to arbitrary file”, is a note. Below are the symptom, SAP recommended solution, CVSS score, references and the affected software components.
Description
Symptom
An attacker can discover information relating to arbitrary files.
Solution
Please implement the correction instruction or the relevant Support Package (SP).
Reason and prerequisites
Information such as server information, processes, installed products, versions of those products, landscape configuration data, and users can be discovered using iXML by attempting to serve a program. This information may be used by an attacker to further target the system.
CVSS
Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N
References
This note refers to
Affected components
- SAP_BASIS versions 640 to 730, and 731
Full note on SAP: SAP Support Launchpad note 1715040
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
