SAP Security Note
SAP security note 1447337, "User can obtain information without authorization", is released on February 8, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
An unauthorized user can obtain information about Web Dynpro ABAP trace data. This information could be used to make an attack on a Web Dynpro ABAP application.
Solution
Import the relevant Support Package or implement the relevant correction instructions.
Reason and prerequisites
An unauthorized user can view such information as the structure of the UI tree, for example.
CVSS
Score 0
References
Full note on SAP: SAP Support Launchpad note 1447337
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



