SAP Security Note
SAP security note 1896642, "Potential information disclosure relating to Integration Technology ALE", is a note released on December 10, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can obtain information about the user name and password of the <SID>ADM operating system user. This information could be used for a targeted attack against an SAP system.
Exposure of sensitive user credentials can allow attackers to perform targeted attacks, potentially compromising the security and integrity of the SAP environment.
Solution
- Implement Correction Instructions: use the Note Assistant (transaction SNOTE) to apply the correction instructions provided in the SAP Note.
- Import Relevant Support Package: import the appropriate Support Package for your SAP_BASIS version, then maintain the logical file paths in the ALE scenario using transaction WEWL or table EDIPOWHITELIST.
References
Full note on SAP: SAP Support Launchpad note 1896642
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
