Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to database server file system, SAP security note 2070691

SAP Note 2070691
SAP Security Note
High priority

SAP security note 2070691, "Potential information disclosure relating to database server file system", is a program error note released on 12.02.2019. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released on12.02.2019

Description

Symptom

An attacker can discover information that is stored in files on the operating system level on the database server. This information could be used to allow the attacker to specialize their attacks against the database server.

UPDATE 11th February 2019: This note has been re-released with updated "validity" information. Additionally, CVSS information is also made available.

Solution

Implement code correction.

Or implement the valid Support Package (Release to Customer planned December 2014):

Reason and prerequisites

Information such as configuration data or user passwords can be discovered using ST-PI. This information may be used by an attacker to further target the database server.

CVSS

Score 7.7 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2070691

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More