Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to SRM-MDM, SAP security note 1661781

SAP Note 1661781

SAP security note 1661781, "Potential information disclosure relating to SRM-MDM". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can discover information relating to SRM-MDM Catalog. This information could be used to allow the attacker to specialize their attacks against SRM-MDM Catalog.

Solution

The solution will be available from:

  • Catalog 7.01 SP07 Patch01 onwards for Catalog 7.01
  • Catalog 3.0 SP11 Patch06 onwards for Catalog 3.0
  • Catalog 7.01 SP00 Patch10 onwards for Catalog 7.01 NW7.3
  • Catalog 3.0 SP00 Patch04 onwards for Catalog 3.0 NW7.3

Reason and prerequisites

Information such as the Item details can be discovered using SRM-MDM Catalog. This information may be used by an attacker to further target SRM.

CVSS

Score 5.8 Vector: AV:N/AC:M/AU:N/C:P/I:P/A:N

References

Affected components

  • SRM_MDM_CAT: 3.0 to 3.0
  • SRM_MDM_CAT: 7.01 to 7.01
  • SRM_MDM_CAT: 3.73 to 3.73
  • SRM_MDM_CAT: 7.31 to 7.31

Full note on SAP: SAP Support Launchpad note 1661781

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More