Release date: 2011-11-11
Updated on: 2011-11-23
Affected Systems:
SAP NetWeaver
Description:
--------------------------------------------------------------------------------
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
SAP NetWeaver J2EE MeSync has an information leakage vulnerability. Attackers can obtain sensitive information such as the mobile engine version and technical staff name without verification.
<* Source: Alexander Polyakov
Link: http://erpscan.com/advisories/dsecrg-11-034-sap-netweaver-j2ee-mesync-%E2%80%93-information-disclose
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
SAP has released a Security Bulletin (DSECRG-11-034) and patches for this:
DSECRG-11-034: SAP NetWeaver J2EE MeSync-Information Disclose
Link: http://erpscan.com/advisories/dsecrg-11-034-sap-netweaver-j2ee-mesync-%E2%80%93-information-disclose