SAP Security Note
Medium priority
SAP security note 1888167, "SMB Relay in Runtime Analysis", is a program error note released on September 10, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential SMB Relay attack in the following components: Runtime Analysis
Solution
The programs specified in the correction instructions will not accept full path names, but only the file name after the correction. Please apply the support package mentioned in this note or the respective correction instructions.
Reason and prerequisites
The programs specified in the correction instructions contain vulnerabilities through which an attacker can potentially read server credentials on another remote server, possibly disclosing confidential information.
CVSS
Score 2.3 Vector: AV:A/AC:M/AU:S/C:P/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 1888167
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
