SAP security note 1505000, “Security issues related to LAC.” Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1505000 addresses security vulnerabilities in the Live Auction Cockpit Web Presentation Server (LACWPS). These vulnerabilities arise from outdated programming practices and coding errors that could expose sensitive information to unauthorized users.
Solution
The identified vulnerabilities have been addressed in the following releases/patches of Live Auction:
- LACWPS 6.0 Patch 6
- LACWPS 5.0 Patch 5
Reason and prerequisites
- Internal Data Exposure: System internal data was being revealed through error messages, potentially allowing hackers to exploit the program.
- Debug Code Presence: Debugging code used during development may provide attackers opportunities to access sensitive information.
- Predictable Random Number Generation: Security-critical implementations using predictable random number generators could be exploited.
- Improper Scope of Variables: Instance variables and methods had scopes that allowed unauthorized access to assumed hidden data.
References
This note refers to
Affected components
- SRM-LA (Supplier Relationship Management > Live Auction)
- LACWPS 5.0
- LACWPS 6.0
- SRM_SERVER 500
- SRM_SERVER 550
- SRM_SERVER 600
- SRM_SERVER 700
- SRM_SERVER 701
Full note on SAP: SAP Support Launchpad note 1505000
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
