SAP Security Note
High priority
SAP security note 1849892, "Potential information disclosure relating to WEC-APP-PAY", is a program error note released on 14.04.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can discover information relating to WEC-APP-PAY. This information could be used to allow the attacker to specialize their attacks against WEC-APP-PAY.
Solution
Apply the patch.
Reason and prerequisites
Sensitive information can be discovered using WEC-APP-PAY. This information may be used by an attacker to further target WEC-APP-PAY.
This vulnerability is only exploitable with administrator privileges.
Full note on SAP: SAP Support Launchpad note 1849892
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



