Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to SLM, SAP security note 1894049

SAP Note 1894049
High priority

SAP security note 1894049, "Potential information disclosure relating to SLM", was released on January 14, 2014. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Upgrade – general > Software Lifecycle Manager
PriorityCorrection with high priority
StatusReleased for Customer
Released onJanuary 14, 2014

Description

Symptom

An attacker could make an HTTP GET request to certain URLs provided by the Software Lifecycle Manager (SLM) to obtain sensitive information that can be used to perform more sophisticated attacks.

This vulnerability allows for potential information disclosure, which might aid attackers in building more targeted attacks against your systems.

Solution

Apply the appropriate patch for the SWLIFECYCL component. The required Support Package levels are:

  • NW701 SP11 or later
  • NW702 SP11 or later
  • NW710 SP14 or later
  • NW711 SP9 or later
  • NW720 SP5 or later
  • NW730 SP7 or later
  • NW731 SP6 or later

Reason and prerequisites

The issue arises from some JSP pages developed for testing JNET technology that were not removed before the application was delivered to customers.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 1894049

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More