SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533660397 | vendor advisory |
https://launchpad.support.sap.com/#/notes/2845183 | vendor advisory permissions required |