SAP Security Note
High priority
SAP security note 1663732, "Potential information disclosure relating to SAProuter", is released on August 14, 2012. Below are the symptom, CVSS score, reason, SAP recommended solution, references and the affected software components.
Description
Symptom
An attacker can discover information relating to SAProuter connections if the SAProuter is used to communicate and if it is started with the option -n. This information could be used to allow the attacker to specialize their attacks against the application server.
Solution
Use an SAProuter with the patch level specified in this SAP Note or a higher patch level.
Reason and prerequisites
Information such as the user names, processes, or configuration data can be discovered using the SAProuter. This information may be used by an attacker to further target the application server.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
This note refers to
Affected components
- KRNL32NUC
- KRNL32UC
- KRNL64NUC
- KRNL64UC
- SAP_BASIS
- KERNEL
Full note on SAP: SAP Support Launchpad note 1663732
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
