SAP security note 2157458, "Potential Information Disclosure in Internet Communication Framework", is released on August 11, 2015. Below are the symptom and the SAP recommended solution.
Description
Symptom
An attacker can discover information related to HTTP request header attributes. This information could be utilized to tailor attacks against SAP applications.
Solution
The correction in the Internet Communication Framework removes sensitive information before the HTTP request is passed to the application. To mitigate this vulnerability:
- Implement the SAPKB73014 Support Package
- Apply the correction instructions detailed in SAP Note 2157458 Correction Instructions
Reason and prerequisites
This note is applicable if you have implemented SAP Note 1559556, which addresses visible security session ID cookies in HTTP requests.
CVSS
Score 4.3 / 10 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2157458
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
