Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to server information, SAP security note 2148854

SAP Note 2148854
Medium priority

SAP security note 2148854, “Potential information disclosure relating to server information”, was released on July 14, 2015. Below are the symptom and SAP recommended solution.

ComponentSAP HANA > SAP HANA Application Services > SAP HANA Extended Application Services (HAN-AS-XS)
PriorityMedium priority
StatusReleased for Customer
Released onJuly 14, 2015

Description

Symptom

An attacker can discover information relating to the server information of the SAP Web Dispatcher. This information could be used to allow the attacker to specialize their attacks against the SAP Web Dispatcher and backend systems served by it.

The issue affects the standalone SAP Web Dispatcher, the internal HANA Web Dispatcher, and the Internet Communication Manager.

Solution

  • Standalone SAP Web Dispatcher or Internet Communication Manager: Apply the Kernel patch referenced in this SAP Note.
  • Internal HANA Web Dispatcher: Apply SAP HANA SPS 9 Database Revision 97 or higher.

CVSS

Score 5.0 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2148854

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More