SAP Security Note
Medium priority
SAP security note 2191529, "Potential Information Disclosure in Transaction SCI (Code Inspector)", is a program error note released on 08.09.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to transaction SCI (ABAP Code Inspector).
- Existing check results of “ABAP Code Inspections” (Transaction SCI, Code Inspector) can be seen.
- The attacker cannot run new checks.
- The attacker needs to know the username, check name, and check version of an SCI Code Check.
- The attacker does not have access to the ABAP code itself.
- The attacker does not have any access to real business data.
Solution
Immediate solution: Switch the service inspection to inactive; or better: directly delete this service. This service is a leftover from early tests. It is not needed in any business scenario or for any other function. De-activation or deletion of this service has no negative consequences whatsoever.
Final solution: This service is (or will be) removed with the following Support Packages:
- Netweaver 7.00, SAP_BASIS 700, Support Package 33
- Netweaver 7.01, SAP_BASIS 701, Support Package 18
- Netweaver 7.02, SAP_BASIS 702, Support Package 18
- Netweaver 7.30, SAP_BASIS 730, Support Package 12
- Netweaver 7.31, SAP_BASIS 731, Support Package 16
- Netweaver 7.40, SAP_BASIS 740, Support Package 11
Reason and prerequisites
The reading of information is only possible in the following situation:
- Start transaction
SICF, execute with “Hierarchy Type” = “Service”. - In the hierarchy of “Virtual Hosts / Services” navigate to
/default_host/sap/public/bc/trex/test/. Here the serviceinspectionis active.
If this service is not active, then no attack is possible.
CVSS
Score 4.3 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2191529
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



