SAP Internet Transaction Server Information Disclosure Vulnerability
BID:8515
Info
SAP Internet Transaction Server Information Disclosure Vulnerability
| Bugtraq ID: | 8515 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0747 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | This vulnerability was reported by Martin Eiszner <[email protected]>. |
| Vulnerable: |
SAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 |
| Not Vulnerable: | |
Discussion
SAP Internet Transaction Server Information Disclosure Vulnerability
A vulnerability has been discovered in SAP Internet Transaction Server (SITS)that could allow an attacker to obtain sensitive information. The problem occurs due to SITS disclosing sensitive local filesystem information when handling malformed requests. Specifically, an attacker who submits a request containing invalid values will receive an error response message in return. This response may contain sensitive information.
A vulnerability has been discovered in SAP Internet Transaction Server (SITS)that could allow an attacker to obtain sensitive information. The problem occurs due to SITS disclosing sensitive local filesystem information when handling malformed requests. Specifically, an attacker who submits a request containing invalid values will receive an error response message in return. This response may contain sensitive information.
Exploit / POC
SAP Internet Transaction Server Information Disclosure Vulnerability
The following sample request has been provided.
http://www.server.name/scripts/wgate/pbw2/!?
with params:
~runtimemode=DM&
~language=en&
~theme=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&
The following sample request has been provided.
http://www.server.name/scripts/wgate/pbw2/!?
with params:
~runtimemode=DM&
~language=en&
~theme=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&
Solution / Fix
SAP Internet Transaction Server Information Disclosure Vulnerability
Solution:
It has been reported that this issue has been addressed by SAP, however this information has not been confirmed by Symantec. Users are advised to contact SAP for any further details regarding available fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that this issue has been addressed by SAP, however this information has not been confirmed by Symantec. Users are advised to contact SAP for any further details regarding available fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SAP Internet Transaction Server Information Disclosure Vulnerability
References:
References:
- SAP Internet Transaction Server (Martin Eiszner
)