Description
UPDATE 11th February 2019: This note has been re-released with updated “validity” information. Additionally, CVSS information is also made available.
An attacker can discover information that is stored in files on operating system level on the database server.
This information could be used to allow the attacker to specialize their attacks against database server.
Available fix and Supported packages
- ST-PI | 2008_1_700 | 2008_1_700
- ST-PI | 2008_1_710 | 2008_1_710
- ST-PI | 740 | 740
- ST-PI 740 | SAPK-74011INSTPI |
- ST-PI 2008_1_700 | SAPKITLRDU |
- ST-PI 2008_1_710 | SAPKITLREU |
Affected component
- SV-SMG-SDD
Service Data Download
CVSS
Score: 7.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2070691