SAP Security Note
High priority
SAP security note 2070691, "Potential information disclosure relating to database server file system", is a program error note released on 12.02.2019. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information that is stored in files on the operating system level on the database server. This information could be used to allow the attacker to specialize their attacks against the database server.
UPDATE 11th February 2019: This note has been re-released with updated "validity" information. Additionally, CVSS information is also made available.
Solution
Implement code correction.
Or implement the valid Support Package (Release to Customer planned December 2014):
- ST-PI 2008_1_700 – SAPKITLRDU
- ST-PI 2008_1_710 – SAPKITLREU
- ST-PI 740 – SAPK-74011INSTPI
Reason and prerequisites
Information such as configuration data or user passwords can be discovered using ST-PI. This information may be used by an attacker to further target the database server.
CVSS
Score 7.7 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2070691
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



