On the 8th of March SAP released the security note for a vulnerability we reported during an assessment of a SAP landscape. The issue affects the SAP NetWeaver Web Administration Interface. By knowing a special URL a malicious user can acquire version information about the services enabled in the SAP system as well as the operating system used. We wanted to share some details on the issue.
The vulnerability is a bypass of the HTTP Basic Authorization for the SAP Web Administration Interface. It discloses version information about the system respectively operating system, a brief SAP patch level overview and running services including their corresponding ports.
Continue reading