SAP security note 2493171, “Information Disclosure in SAP NetWeaver Instance Agent Service”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, sapstartsrv allows an attacker to access information which would otherwise be restricted.
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
The correction ensures that the affected system components are protected with authentication and authorization and no longer reveal internal information.
Action Required: Implement sapstartsrv with at least the Patch Level mentioned in this SAP Note.
Reason and prerequisites
CCMS Web methods of sapstartsrv are unprotected by authorization checks. This behavior is a programming error.
CVSS
Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
This note refers to
Affected components
- SAP KERNEL 7.21 64-BIT UNICODE: SP012 Patch 000012
- SAP KERNEL 7.22 64-BIT: SP410 Patch 000410
- SAP KERNEL 7.49 64-BIT UNICODE: SP311 Patch 000311
- SAP KERNEL 7.45 64-BIT UNICODE: SP516 Patch 000516
- SAP KERNEL 7.21 32-BIT: SP913 Patch 000913
Full note on SAP: SAP Support Launchpad note 2493171
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




