SAP security note 1903266, "Potential information disclosure relating to offline approval", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to offline approval that is used to deliver SRM. This information could be used to allow the attacker to specialize their attacks against offline approval and SRM.
Solution
Implement the provided support package or follow the correction instructions detailed in the SAP Note.
Reason and prerequisites
Information such as the approval decision can be discovered using offline approval. This information may be used by an attacker to further target offline approval and approval decision.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
Referenced by
Full note on SAP: SAP Support Launchpad note 1903266
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



