SAP security note 1519608, "Password Information Disclosure in Exchange Profile UI," is a note covering the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A security vulnerability has been identified in the Exchange Profile UI of SAP NetWeaver PI that allows users to guess or search for passwords by entering them into the search field. This issue can lead to unauthorized access and compromise data confidentiality.
Solution
A code fix has been provided to prevent the display of passwords upon search. It is essential to apply the relevant patches for the SAP_XIESR component to mitigate this vulnerability.
Fixed versions: SAP NetWeaver PI 7.1 SP03 and onwards.
References
Affected components
- SAP NetWeaver PI 7.1 and later releases
- SAP_XIESR component versions from 7.10 to 7.11+
Full note on SAP: SAP Support Launchpad note 1519608
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



