Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to Mobile Sales, SAP security note 1663819

SAP Note 1663819
SAP Security Note
High priority

SAP security note 1663819, "Potential information disclosure relating to Mobile Sales", is a program error note released on 12.06.2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Basic Functions > Product Configuration
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on12.06.2012
LanguageEnglish

Description

Symptom

An attacker can discover information relating to the database being used in the SAP CRM Mobile Sales Application. This information could be used to allow the attacker to specialize their attacks against the database of the mobile sales installation.

Solution

To correct the issue, apply the Java patch valid for your CRM release from the SAP Service Marketplace.

Reason and prerequisites

Information such as the user password can be discovered using SAP CRM Mobile Sales. This information may be used by a malicious user to further target the stored data of the Mobile Sales installation.

CVSS

Score 0

Affected components

  • SAP-IPCMSA: 5.0 to 5.0
  • SAP-IPCMSA: 6.0 to 6.0
  • SAP-IPCMSA: 700 to 700
  • SAP-IPCMSA: 701 to 701

Full note on SAP: SAP Support Launchpad note 1663819

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.