Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to Code Inspector, SAP security note 2150197

SAP Note 2150197
SAP Security Note
Low priority

SAP security note 2150197, "Potential information disclosure relating to Code Inspector", is a program error note released on 09.06.2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > ABAP Workbench, Java IDE and Infrastructure > Workbench Tools: Editors, Painter, Modeler > ABAP Check Frameworks – ABAP Test Cockpit, Code Inspector
CategoryProgram error
PriorityCorrection with low priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on09.06.2015
LanguageEnglish

Description

Symptom

An attacker can discover information relating to ABAP source code displayed in Code Inspector. This information could be used to allow the attacker to specialize their attacks against SAP ABAP applications.

Solution

Please apply the Support Package mentioned, or the respective correction instruction.

The correction provided adds additional authorization checks for objects S_ADMI_FCD (ID ‘S_ADMI_FCD’, FIELD ‘ST0R’) and S_DEVELOP (ID ‘ACTVT’, FIELD ’03’).

Reason and prerequisites

Information such as the quality of ABAP source code can be discovered using Code Inspector. This information may be used by an attacker to further target ABAP applications.

CVSS

Score 2.1 Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2150197

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More