Description
Certain error messages are so specific that they enable you to determine the dataset in a back-end system. This is not required.
Example: The error message ‘Instance & does not exist’ can be used maliciously.
The symptom described here can put the confidentiality of the dataset of a system at risk. However, the risk potential is very small.
Available fix and Supported packages
- ECC-SE | 501 | 501
- ECC-SE | 602 | 602
- ECC-SE | 603 | 603
- ECC-SE | 604 | 604
- ECC-SE | 605 | 605
- ECC-SE 501 | SAPK-50106INECCSE |
- ECC-SE 603 | SAPK-60305INECCSE |
- ECC-SE 604 | SAPK-60406INECCSE |
- ECC-SE 605 | SAPK-60501INECCSE |
- ECC-SE 602 | SAPK-60207INECCSE |
- ECC-SE 603 | SAPK-60306INECCSE |
- ECC-SE 604 | SAPK-60407INECCSE |
- ECC-SE 605 | SAPK-60502INECCSE |
Affected component
- PA-PA-SOA
Enterprise Services
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1438526