SAP security note 2193424, “Potential information disclosure relating to NavigationServlet”, is released on January 12, 2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information related to NavigationServlet. This information could be leveraged to specialize attacks targeting NavigationServlet, potentially compromising system integrity.
Solution
Apply the appropriate support package patches to address this vulnerability. Refer to the Support Package Patches for detailed information on available fixes.
CVSS
Score 5.0 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
References
- 2305555 – Collective Note: SAP NetWeaver 7.31 SP18 – Composition Platform
- 2270701 – Collective Note: SAP NetWeaver 7.30 SP15 – Composition Platform
Affected components
- EP-RUNTIME 7.30, 7.31, 7.40, 7.50
Full note on SAP: SAP Support Launchpad note 2193424
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
