Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to Real Time Collaboration Chat, SAP security note 2255990

SAP Note 2255990
SAP Security Note
Medium priority

SAP security note 2255990, “Potential information disclosure relating to Real Time Collaboration Chat”, is a program error note released on 08.03.2016. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > SAP Enterprise Portal (On Premise) > Real Time Collaboration
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on08.03.2016
LanguageEnglish

Description

Symptom

An attacker can discover information relating to user data who uses Real Time Collaboration (RTC) Chat. This information could be used to allow the attacker to specialize their attacks against further user data in Real Time Collaboration.

Solution

Under the "Support Packages & Patches" tab within this note, you can check for the appropriate SP and Patch levels fixing this issue.

Reason and prerequisites

Information such as user name, group name, and role name was exposed in WD chat for anonymous users when using the Web Dynpro chat application called Real Time Collaboration. When any user was using the Instant Messaging application, they could select from the list the portal group, role, or user. This information may be used by an attacker to further target the end user or Real Time Collaboration.

CVSS

Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2255990

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More