S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

SAP NetWeaver ICM Information Disclosure Vulnerability Scanner

Online SAP NetWeaver ICM Information Disclosure Vulnerability Scanner

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
30
Vulnerabilities Found
confirmed findings
References
Detail

SAP Internet Communication Framework (ICF) is enabled and the info service can be accessed anonymously through the /sap/public/info URL. This service leaks sensitive information about the SAP platform, such as operating system version, SAP version, IP address and other information.

Solution Advice

It's recommended to restrict access to the ICF service (if not used inside the organization). The ICF service can be deactivated using the SICF transaction.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Online SAP NetWeaver ICM Information Disclosure Vulnerability Scanner | S4E