SAP security note 1751310, "Potential information disclosure relating to parameters", is a security note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to one R/3 profile parameter. This information could allow the attacker to specialize their attacks against an SAP system.
Solution
As a result of a program change, the affected function module now only supports the reading of the affected landscape information from within the SAP system itself.
This program change is contained in the Support Packages specified below. For older Support Packages, you can implement the program change from this note using SNOTE.
Reason and prerequisites
Information such as certain landscape configuration data can be discovered using BC-DB-SDB-CCM. This information may be used by an attacker to further target the SAP system.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1751310
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



