SAP Security Note
Medium priority
SAP security note 2255990, “Potential information disclosure relating to Real Time Collaboration Chat”, is a program error note released on 08.03.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to user data who uses Real Time Collaboration (RTC) Chat. This information could be used to allow the attacker to specialize their attacks against further user data in Real Time Collaboration.
Solution
Under the "Support Packages & Patches" tab within this note, you can check for the appropriate SP and Patch levels fixing this issue.
Reason and prerequisites
Information such as user name, group name, and role name was exposed in WD chat for anonymous users when using the Web Dynpro chat application called Real Time Collaboration. When any user was using the Instant Messaging application, they could select from the list the portal group, role, or user. This information may be used by an attacker to further target the end user or Real Time Collaboration.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2255990
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
