SAP Security Note
Medium priority
SAP security note 1784772, “Potential information disclosure relating to LCM”, is a program error note released on 09.04.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to LCM in BI4. This information could be used to allow the attacker to specialize their attacks against LCM and BI4.
Solution
Customers should install patch 2.16 or Support Pack 4 to address this issue.
Reason and prerequisites
Information such as user passwords can be discovered using LCM.
This information may be used by an attacker to further target BI4.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1784772
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
