SAP security note 2191290, “Potential information disclosure relating to AS Java”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to AS Java by using UME. This information could be used to allow the attacker to specialize their attacks against AS Java.
Solution
Update your AS Java to a release or Support Package (SP) in which the issue is fixed. See the "Validity" and "SP Patch Level" sections of this note for details and available patches.
Reason and prerequisites
Information such as user passwords can be discovered using UME. This information may be used by an attacker to further target AS Java.
CVSS
Score 3.5 Vector: AV:N/AC:M/PR:S/UI:N/S:U/C:P/I:N/A:N
References
Referenced by
- 2001630 – User/password migration and users informed (UME: ABAP / LDAP)
- 1760085 – Migrating users with passwords included (UME:LOCAL DB)
- 2305548 – Central note for SAP NetWeaver 7.31 SP18 Application Server Java
- 2241266 – Collective Note: SAP NetWeaver 7.5 SP02 – Application Server Java (AS Java)
- 2270677 – Collective Note: SAP NetWeaver 7.30 SP15 – Application Server Java
- 2206761 – Collective Note: SAP NetWeaver 7.02 SP18 – Application Server Java
- 2236119 – Corrections for unified rendering up to SAP_BASIS 711/16 I (UR-Mimes)
Affected components
- SAP-JEECOR 7.00 to 7.02
- SERVERCORE 7.10 to 7.50
Full note on SAP: SAP Support Launchpad note 2191290
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
