SAP security note 2073000, “Potential information disclosure relating to UserID”, is a program error note released on 28.11.2014. Below is the security information published by SAP for this note.
Description
Symptom
An attacker can discover information relating to CRM-IC-FRW who uses POLLING. This information could be used to allow the attacker to specialize their attacks against CRM-IC-FRW and POLLING.
Reason and prerequisites
Information such as user information can be discovered using CRM-IC-FRW. This information may be used by an attacker to further target Users.
Solution
Apply the attached correction instruction.
Affected components
| Software Component | From | To | |——————–|——|——| | CRMUIF | 600 | 600 | | WEBCUIF | 700 | 700 | | WEBCUIF | 701 | 701 | | WEBCUIF | 731 | 731 | | WEBCUIF | 730 | 730 | | WEBCUIF | 746 | 746 | | WEBCUIF | 747 | 747 |
Additional information
For more details and updates, visit the SAP Support Portal.
*Credits to RedRays.io for supporting the information provided.*
Full note on SAP: SAP Support Launchpad note 2073000
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
