SAP Security Note
High priority
SAP security note 1966995, "Potential information disclosure relating to WebDynpro Application", is a program error note released on May 13, 2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to the system. This information could be used to allow the attacker to specialize their attacks against Web Dynpro Applications.
Solution
Implement the note and apply prerequisites for attached manual activities.
Reason and prerequisites
Information such as the landscape configuration data can be discovered using Web Dynpro Application. This information may be used by an attacker to further target pages and applications of Web Dynpro.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
Affected components
- SAP_UI: Version 740
- SAP_BASIS: Versions 700 to 740
Full note on SAP: SAP Support Launchpad note 1966995
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
