SAP Security Note
High priority
SAP security note 1663819, "Potential information disclosure relating to Mobile Sales", is a program error note released on 12.06.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to the database being used in the SAP CRM Mobile Sales Application. This information could be used to allow the attacker to specialize their attacks against the database of the mobile sales installation.
Solution
To correct the issue, apply the Java patch valid for your CRM release from the SAP Service Marketplace.
Reason and prerequisites
Information such as the user password can be discovered using SAP CRM Mobile Sales. This information may be used by a malicious user to further target the stored data of the Mobile Sales installation.
CVSS
Score 0
Affected components
- SAP-IPCMSA: 5.0 to 5.0
- SAP-IPCMSA: 6.0 to 6.0
- SAP-IPCMSA: 700 to 700
- SAP-IPCMSA: 701 to 701
Full note on SAP: SAP Support Launchpad note 1663819
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




