SAP security note 1658646, “Potential information disclosure relating to NetWeaver BPM”, is a program error note released on 10.04.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to internal interfaces who use SAP NetWeaver BPM. This information could be used to allow the attacker to specialize their attacks against internal interfaces and SAP NetWeaver BPM.
Solution
To correct this problem, apply the patch matching your support package version as listed in the patch table as per the instructions in the SAP NetWeaver Support Package Stack Guide.
Reason and prerequisites
Information such as one isolated internal development unit tests can be discovered using SAP NetWeaver BPM. This information may be used by an attacker to further target this specific class.
Full note on SAP: SAP Support Launchpad note 1658646
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
