High priority
SAP security note 1828885, "Potential Information Disclosure Relating to Managed Systems", was released on January 14, 2014. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information related to files of SAP systems used in Solution Manager without needing any end-user login credentials. This information could be used to specialize attacks against Managed systems.
Solution
This potential threat has been fixed with Solution Manager 7.1 SP05. It is recommended to upgrade to this support package to mitigate the issue.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1828885
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
