Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to WEC-APP-PAY, SAP security note 1849892

SAP Note 1849892
SAP Security Note
High priority

SAP security note 1849892, "Potential information disclosure relating to WEC-APP-PAY", is a program error note released on 14.04.2015. Below are the symptom and SAP recommended solution.

ComponentWeb Channel Experience Management > Web Channel Applications > Web Channel: Basic Functions – Payment Method
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on14.04.2015
LanguageEnglish

Description

Symptom

An attacker can discover information relating to WEC-APP-PAY. This information could be used to allow the attacker to specialize their attacks against WEC-APP-PAY.

Solution

Apply the patch.

Reason and prerequisites

Sensitive information can be discovered using WEC-APP-PAY. This information may be used by an attacker to further target WEC-APP-PAY.

This vulnerability is only exploitable with administrator privileges.

Full note on SAP: SAP Support Launchpad note 1849892

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More