SAP security note 1661551, "Potential information disclosure relating to SRM-MDM Catalog". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to SRM-MDM Catalog. This information could be used to allow the attacker to specialize their attacks against SRM-MDM Catalog.
Solution
Implement the correction contained in this note or install the corresponding support package.
Reason and prerequisites
Information such as the Item details can be discovered using SRM-MDM Catalog. This information may be used by an attacker to further target SRM.
For Java corrections, implement the corresponding Catalog patches mentioned in Note 1661781.
CVSS
Score 5.8 Vector: AV:N/AC:M/AU:N/C:P/I:P/A:N
Affected components
- SRM_SERVER: Versions 700 and 701
Full note on SAP: SAP Support Launchpad note 1661551
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
