SAP security note 2167813, “Potential information disclosure relating to Enterprise Services Repository”, is a program error note released on 12.01.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information related to the Enterprise Services Repository (ESR). This information could be used to tailor attacks against ESR.
Solution
This issue is fixed with the Support Packages and Patches referenced by this SAP Note.
Reason and prerequisites
Information such as service user passwords can be discovered using Enterprise Services Builder. This information may be leveraged by an attacker to further target the Enterprise Services Repository.
CVSS
Score 4.0 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N
References
Referenced by
- 2305563 – Collective note: SAP NETWEAVER 7.31 SP18 – Process Orchestration (PI)
- 2270711 – Collective Note: SAP NetWeaver 7.30 SP15 – Process Integration
- 2270704 – Collective Note: SAP NetWeaver 7.30 SP15 – Enterprise Services Repository
- 2236119 – Corrections for unified rendering up to SAP_BASIS 711/16 I (UR-Mimes)
- 2229417 – Corrections for unified rendering 701/18 II (UR Mimes)
Affected components
- NWCEIDE 7.50
- SAP_XIESR 7.10 to 7.50
- SAP_XITOOL 7.00 to 7.50
- HM-XITEST 7.10 to 7.40
Full note on SAP: SAP Support Launchpad note 2167813
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



