<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ERP on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/erp/</link>
    <description>Recent content in ERP on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 30 Jun 2016 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/erp/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Some infos about SAP Security Note 2258786</title>
      <link>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</link>
      <pubDate>Thu, 30 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</guid>
      <description>&lt;p&gt;On the 8th of March SAP released the security note for a vulnerability we reported during an assessment of a SAP landscape. The issue affects the SAP NetWeaver Web Administration Interface.  By knowing a special URL a malicious user can acquire version information about the services enabled in the SAP system as well as the operating system used.  We wanted to share some details on the issue.&lt;/p&gt;&#xA;&lt;p&gt;The vulnerability is a bypass of the HTTP Basic Authorization for the &lt;a href=&#34;https://help.sap.com/saphelp_nw73/helpdata/en/4b/c1cd5cfb0050e9e10000000a15822b/content.htm?frameset=/en/48/3e191a252f72d0e10000000a42189c/frameset.htm&amp;amp;current_toc=/en/62/d678c5330a4992bc6fe927e6137c9d/plain.htm&amp;amp;node_id=155&amp;amp;show_children=false&#34;&gt;SAP Web Administration Interface&lt;/a&gt;. It discloses version information about the system respectively operating system, a brief SAP patch level overview and running services including their corresponding ports.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
