SAP security note 2260895, “Potential information disclosure relating to Explorer web application server”. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information related to the SAP BusinessObjects Explorer web application server. This information could be used to tailor attacks specifically against the Explorer web application server.
Solution
The issue has been fixed in the patches listed in the "Support Package Patches" section below.
Information about web server specifications (web server type, version, etc.) and the Java environment has been removed from the config.jsp page (http://xxx/explorer/config.jsp). For Business Intelligence Platform maintenance schedule and strategy, see SAP Note 2144559 in the References section.
Reason and prerequisites
An attacker can discover information relating to the SAP BusinessObjects Explorer web application server. This information could enable the attacker to specialize their attacks against the Explorer web application server.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2260895
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
