SAP BusinessObjects 'HappyAxis2.jsp' Information Disclosure

medium Nessus Plugin ID 44342

Synopsis

A web application running on the remote host is leaking information.

Description

The SAP BusinessObjects installation on the remote web server is leaking information via '/BusinessProcessBI/axis2-web/HappyAxis.jsp'.
This page contains debugging information such as local file paths, operating system version, and Java version.

A remote attacker could use this information to mount further attacks.

This version of BusinessObjects reportedly has several other vulnerabilities, though Nessus has not checked for those issues.

Solution

Restrict access to this web page.

See Also

http://www.nessus.org/u?c9cfae68

https://seclists.org/fulldisclosure/2010/Jan/572

Plugin Details

Severity: Medium

ID: 44342

File Name: sap_bobj_happyaxis_info_leak.nasl

Version: 1.13

Type: remote

Family: CGI abuses

Published: 2/1/2010

Updated: 1/19/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: cpe:/a:sap:businessobjects

Required KB Items: www/sap_bobj

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 1/18/2010

Reference Information

BID: 37900

Secunia: 38217