Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to Enterprise Services Repository, SAP security note 2167813

SAP Note 2167813SAP Security NoteHigh priority

SAP security note 2167813, “Potential information disclosure relating to Enterprise Services Repository”, is a program error note released on 12.01.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > NetWeaver Process Integration (PI) > Integration Builder – Design
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on12.01.2016
LanguageEnglish

Description

Symptom

An attacker can discover information related to the Enterprise Services Repository (ESR). This information could be used to tailor attacks against ESR.

Solution

This issue is fixed with the Support Packages and Patches referenced by this SAP Note.

Reason and prerequisites

Information such as service user passwords can be discovered using Enterprise Services Builder. This information may be leveraged by an attacker to further target the Enterprise Services Repository.

CVSS

Score 4.0 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

References

Affected components

  • NWCEIDE 7.50
  • SAP_XIESR 7.10 to 7.50
  • SAP_XITOOL 7.00 to 7.50
  • HM-XITEST 7.10 to 7.40

Full note on SAP: SAP Support Launchpad note 2167813

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More