SAP security note 2093939, "Potential information disclosure relating to remote system." Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to a remote system that is used from the Axis adapter to deliver messages. This information could be used to allow the attacker to specialize their attacks against the remote system and Axis adapter.
Solution
Download and apply the SAP XI Adapter Framework Component according to your NetWeaver version and Support Package (SP) Level as described in the Download section of this Note.
Reason and prerequisites
Some information relating to the remote system can be discovered using the Axis adapter. This information may be used by an attacker to further target the remote system.
CVSS
Score 3.5 / 10 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N
References
Affected components
- SAP_XIAF: Versions 7.00 to 7.40
- SAP-XIAFC: Versions 7.00 to 7.02
Full note on SAP: SAP Support Launchpad note 2093939
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
