Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to XMLForms, SAP security note 2045668

SAP Note 2045668SAP Security NoteMedium priority

SAP security note 2045668, “Potential information disclosure relating to XMLForms”, is a note released on 11.11.2014. Below is the security information published by SAP for this note.

ComponentEnterprise Portal > Enterprise Portal – Knowledge Management and Collaboration > KM Tools > XF Builder
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on11.11.2014

Description

Symptom

An attacker can discover information relating to XMLForms. This information could be used to allow the attacker to specialize their attacks against XMLForms and AS Java.

Reason and prerequisites

Information such as runtime environment information can be discovered using XMLForms. This information may be used by an attacker to further target XMLForms and AS Java.

Solution

See the SP Patch Level section of this SAP Note for details. You can download the note in SNOTE format or view the PDF version:

Affected components

  • KMC-CM versions 7.00 to 7.40

References

Full note on SAP: SAP Support Launchpad note 2045668

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More