SAP Security Note
High priority
SAP security note 2017651, "Potential information disclosure relating to SRM-EBP-CAT", is a program error note released on 15.01.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to SRM-MDM Catalog in SRM-EBP-CAT. This information could be used to allow the attacker to specialize their attacks against SRM-MDM Catalog.
Solution
Implement the correction instructions provided.
Reason and prerequisites
Information such as user passwords can be discovered using a Shoulder Surfer attack. This information may be used by an attacker to further target SRM-MDM Catalog.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
References
Affected components
- SRM_SERVER 550
- SRM_SERVER 700
- SRM_SERVER 701
- SRM_SERVER 702
- SRM_SERVER 713
Full note on SAP: SAP Support Launchpad note 2017651
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




