SAP security note 1935222, "Potential information disclosure relating to logon application", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to the Java server who uses the logon application. This information could be used to allow the attacker to specialize their attacks against the Java server and the logon application.
Solution
Apply the patches listed in the “SP Patch Level” section of the note that are relevant to the release and SP of your server.
Reason and prerequisites
Information such as the installed products in the customer’s landscape can be discovered using the logon application. This information may be used by an attacker to further target the Java server.
This note is related to Note 1651004 and Cross-Frame Scripting. As stated there, this is not a vulnerability of the Java server and you should have that in mind when deciding whether to apply it.
This note is relevant if you can see the text “An unexpected problem has occurred. Please contact your system administrator and show them this message.” when you access the NetWeaver Java server. If this is the case, this note explains what the problem is.
Affected components
- EPBC2 7.00 to 7.02
- SAP_JTECHS 7.00 to 7.02
- J2EE-APPS 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40
Full note on SAP: SAP Support Launchpad note 1935222
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
