SAP Security Note
High priority
SAP security note 1614706, "Potential information disclosure relating to server version", is a note released on 14.02.2012. Below are the symptom, SAP recommended solution and reason and prerequisites.
Description
Symptom
An attacker can discover information related to the portal version that uses EPCM APIs. This information could be leveraged to tailor attacks against the portal.
Solution
Refer to the SP Patch Level tab in the SAP Note to view the relevant versions and the corresponding fixes.
Reason and prerequisites
Information such as portal versions can be extracted using EPCM objects, potentially aiding attackers in targeting SAP NetWeaver Portal more effectively.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1614706
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




