SAP security note 1520231, “Potential information disclosure relating to usernames”, is a note released on November 25, 2014. Below is the security information published by SAP for this note.
Description
#### Symptom A malicious user who uses MFG-MII can discover information relating to usernames and server information. This information could be used to allow the malicious user to specialize their attacks against MFG-MII.
#### Other Terms Information disclosure, MFG-MII
#### Reason and Prerequisites Information such as the installed products, versions of those products, and landscape configuration data or user passwords can be discovered through the use of MFG-MII. This information can potentially be used by a malicious user to further target MFG-MII.
#### Solution All the malicious code has been removed/fixed in MII 12.1 SP06 and MII 12.2 SP02. Please update to the above-mentioned releases to get the changes.
Full note on SAP: SAP Support Launchpad note 1520231
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



