SAP security note 1619539, "Potential information disclosure relating to KM UI", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can discover information relating to KM UI. This information could be used to specialize attacks against KM UI.
Solution
Refer to the Support Package Patch Level section of this SAP Note for detailed instructions on applying the necessary patches to mitigate the vulnerability.
Reason and prerequisites
Information such as runtime environment details can be discovered using KM UI. This information may be leveraged by a malicious user to further target the UI.
CVSS
Score 6.8 Vector: AV:N/AC:L/AU:S/C:C/I:N/A:N
References
- 1889488 – Briefing at Black Hat conference on July 31st, 2013
- 1676329 – KMC in EHP1 for SAP NetWeaver 7.0 SPS11 – Add-on
- 1494028 – KMC in SAP EHP2 for SAP NetWeaver 7.0 SPS06
Affected components
- EPBC2 (7.00 to 7.02)
- KMC-BC (7.30 to 7.31)
- EP-CM (6.0_640)
Full note on SAP: SAP Support Launchpad note 1619539
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
