SAP Security Note
High priority
SAP security note 2091768, "Potential information disclosure relating to SAPCCMS", is a program error note released on 10.03.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover the value of SAP profile parameters via the SAPCCMS WS call ReadProfileParameters.
Solution
Upgrade your kernel to the associated patch level.
Reason and prerequisites
Values of SAP profile parameters can be discovered using the web-service SAPCCMS. This information may be further used by an attacker.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
Referenced by
Full note on SAP: SAP Support Launchpad note 2091768
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
