By exploiting this vulnerability, a remote unauthenticated attacker could get information about the system architecture.
Please fill out the form to download the security advisory.
Further Reading
Missing Authorization Check in SAP NetWeaver
Missing Authorization Check in SAP NetWeaver Impact on Business A remote attacker with low privileges can enumerate all users in the current system client. This information disclosure aids in gathering valid usernames which could be used in subsequent attacks, such as password brute-forcing or social engineering, potentially increasing the attack surface of the system. Vulnerability…
Missing Authorization and Information Disclosure in SAP Business Warehouse
Missing Authorization and Information Disclosure in SAP Business Warehouse Impact on Business A remote attacker can retrieve detailed configuration information about the SAP system and the underlying operating system. This information disclosure could aid an attacker in planning further attacks by identifying specific versions and configurations of the target environment. Vulnerability Details The remote-enabled function…
Missing Authorization and Information Disclosure in RFC Enabled Function Module CMO_COLLECT_INFO_RFC_DEST
Missing Authorization and Information Disclosure in RFC Enabled Function Module CMO_COLLECT_INFO_RFC_DEST Impact on Business A remote authenticated attacker can discover detailed information about installed software components and their versions on the application server. This information disclosure aids in fingerprinting the system, potentially facilitating further attacks by identifying specific vulnerable components. This has a low impact…
