Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to BC-CST, SAP security note 2032840

SAP Note 2032840
SAP Security Note
Medium priority

SAP security note 2032840, "Potential information disclosure relating to BC-CST", is a program error note released on 20.08.2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on20.08.2014
LanguageEnglish

Description

Symptom

This security note replaces security note 1808003.

An attacker can discover information relating to the ABAP Application Server.

Solution

Please install the Support Package (SP) mentioned. An implementation via automatic correction instructions is not possible due to SNOTE restrictions.

If you have already implemented SAP Note 1808003, do not attempt to de-implement it, as this would lead to a syntax error preventing any possibility to log on to the system.

Reason and prerequisites

Information such as the release and patch level of the system can be obtained via a function module. This information may be used by an attacker to further target the ABAP Application Server.

CVSS

Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N

Affected components

  • SAP_BASIS 640
  • SAP_BASIS 700 to 702
  • SAP_BASIS 710 to 730
  • SAP_BASIS 731
  • SAP_BASIS 740

Full note on SAP: SAP Support Launchpad note 2032840

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More