SAP security note 1661748, "Potential information disclosure relating to Auction Monitor", released on 12.06.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information related to the Auction Monitor in LOD-ESO-AS. This information could lead to more specialized attacks against the Auction Monitor and LOD-ESO-AS.
Information such as configuration data can be discovered using LOD-ESO-AS. This information may be used by an attacker to further target the Auction Monitor and SAP Sourcing.
Solution
Fixes have been developed and released in version 5.0 J, Version 5.1 Patch 10, and all Version 7.0 SP and patch releases. Update to the appropriate release/patch version to mitigate this risk.
Full note on SAP: SAP Support Launchpad note 1661748
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
