SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note 2121461.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2016/Oct/31 | third party advisory mailing list |
http://www.securityfocus.com/bid/93509 | vdb entry |
https://www.onapsis.com/research/security-advisories/sap-console-insecure-password-storage | permissions required |