SAP security note 2510269, "Information disclosure vulnerability in SAP NetWeaver Mobile Client". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Truststore key file was getting saved in the local directory of NetWeaver Mobile Client, which could be decrypted and used for manipulating the Custom Certificates.
Solution
Code changes have been made to adapt to a more secure encryption method. The truststore master key is no longer stored in the local directory of SAP NetWeaver Mobile Client.
Fix is available from 7.11 SP15 Patch 01 onwards.
Upgrade the client to the above version or higher.
Reason and prerequisites
Truststore key file was getting saved under the local directory of the NetWeaver Mobile client folder.
You are using NetWeaver Mobile Client 7.11 SP16 Patch 00 or below.
CVSS
Score 3.8 Vector: AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
References
Affected components
- NWMCLIENTSETUP: Versions from 7.11 to 7.11
Full note on SAP: SAP Support Launchpad note 2510269
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




