Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to ipcpricing, SAP security note 1545883

SAP Note 1545883
High priority

SAP security note 1545883, "Potential information disclosure relating to ipcpricing", is a note released on August 25, 2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Basic Functions > Product Configuration
PriorityCorrection with high priority
StatusReleased for Customer
Released onAugust 25, 2011

Description

Symptom

A malicious user can discover information relating to ipcpricing who use the IPC client user interface. This information could be used to allow the malicious user to specialize their attacks against ipcpricing and IPC client user interface.

Solution

Implement the patch level of the support pack mentioned in the note.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

References

Affected components

  • SAP-IPCMSA 5.0, 6.0, 700, 701
  • SAP-CRMJAV 5.0, 6.0, 700, 701
  • SAP-CRMWEB 5.0, 6.0, 700, 701
  • SAP-SHRWEB 5.0, 6.0, 700, 701
  • SAP-SHRJAV 5.0, 6.0, 700, 701
  • SAP-CRMAPP 5.0, 6.0, 700, 701
  • SAP-SHRAPP 5.0, 6.0, 700, 701

Full note on SAP: SAP Support Launchpad note 1545883

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More