Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to UserID, SAP security note 2073000

SAP Note 2073000SAP Security NoteLow priority

SAP security note 2073000, “Potential information disclosure relating to UserID”, is a program error note released on 28.11.2014. Below is the security information published by SAP for this note.

ComponentCustomer Relationship Management > Interaction Center WebClient > Framework
CategoryProgram error
PriorityCorrection with low priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on28.11.2014
LanguageEnglish

Description

Symptom

An attacker can discover information relating to CRM-IC-FRW who uses POLLING. This information could be used to allow the attacker to specialize their attacks against CRM-IC-FRW and POLLING.

Reason and prerequisites

Information such as user information can be discovered using CRM-IC-FRW. This information may be used by an attacker to further target Users.

Solution

Apply the attached correction instruction.

Affected components

| Software Component | From | To | |——————–|——|——| | CRMUIF | 600 | 600 | | WEBCUIF | 700 | 700 | | WEBCUIF | 701 | 701 | | WEBCUIF | 731 | 731 | | WEBCUIF | 730 | 730 | | WEBCUIF | 746 | 746 | | WEBCUIF | 747 | 747 |

Additional information

For more details and updates, visit the SAP Support Portal.

*Credits to RedRays.io for supporting the information provided.*

Full note on SAP: SAP Support Launchpad note 2073000

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More