Description
An attacker can discover information relating to the Java server who uses the logon application.
This information could be used to allow the attacker to specialize their attacks against the Java server and the logon application.
Available fix and Supported packages
- EPBC2 | 7.00 | 7.02
- SAP_JTECHS | 7.00 | 7.02
- J2EE-APPS | 7.10 | 7.11
- J2EE-APPS | 7.20 | 7.20
- J2EE-APPS | 7.30 | 7.30
- J2EE-APPS | 7.31 | 7.31
- J2EE-APPS | 7.40 | 7.40
- J2EE ENGINE APPLICATIONS 7.10 | SP017 | 000001
- J2EE ENGINE APPLICATIONS 7.10 | SP018 | 000001
- J2EE ENGINE APPLICATIONS 7.11 | SP012 | 000001
- J2EE ENGINE APPLICATIONS 7.11 | SP013 | 000002
- J2EE ENGINE APPLICATIONS 7.11 | SP014 | 000000
- J2EE ENGINE APPLICATIONS 7.20 | SP009 | 000005
- J2EE ENGINE APPLICATIONS 7.30 | SP010 | 000003
- J2EE ENGINE APPLICATIONS 7.30 | SP011 | 000001
- J2EE ENGINE APPLICATIONS 7.30 | SP012 | 000000
- J2EE ENGINE APPLICATIONS 7.31 | SP009 | 000003
- J2EE ENGINE APPLICATIONS 7.31 | SP010 | 000001
- J2EE ENGINE APPLICATIONS 7.31 | SP012 | 000000
- J2EE ENGINE APPLICATIONS 7.40 | SP004 | 000003
- J2EE ENGINE APPLICATIONS 7.40 | SP005 | 000001
- J2EE ENGINE APPLICATIONS 7.40 | SP007 | 000000
- J2EE ENGINE FACADE 7.10 | SP019 | 000000
- PORTAL FRAMEWORK 7.00 | SP029 | 000004
- PORTAL FRAMEWORK 7.00 | SP030 | 000001
- PORTAL FRAMEWORK 7.00 | SP031 | 000000
- PORTAL FRAMEWORK 7.01 | SP014 | 000003
Affected component
- BC-JAS-SEC
Security, User Management
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1935222