SAP Security Note
Medium priority
SAP security note 1509365, “Potential information disclosure relating to Catalog User”, released on March 13, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can discover information relating to Catalog end user. This information could be used to allow the malicious user to specialize their attacks against Catalog end user.
Solution
Implement the Support Pack SRM MDM Catalog 7.01 SP03.
Reason and prerequisites
Information such as landscape configuration can be discovered using SRM MDM Catalog details. This information may be used by a malicious user to further target end user.
Full note on SAP: SAP Support Launchpad note 1509365
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
