id: sap-router-info-leak info: name: SAPRouter - Routing information leak author: randomstr1ng severity: critical description: SAPRouter contains an information leakage vulnerability. reference: - https://securityforeveryone.com/tools/saprouter-routing-information-leakage-vulnerability-scanner - https://support.sap.com/en/tools/connectivity-tools/saprouter.html metadata: max-request: 1 tags: network,sap,misconfig,saprouter,tcp tcp: - inputs: - data: 00000022524f555445525f41444d002802000000000000000000000000000000000000000000 type: hex host: - "{{Hostname}}" port: 3299 read-size: 2048 matchers: - type: word words: - "Routtab" - "Working directory" - "SAProuter Connection Table" # digest: 4a0a00473045022014a865c9a709f92fee268bb0452e98261e9fe5b9dbe0ba42d4596cf0a9021c0a022100d289a3fff3bc1761b789f68cc87a44cc0b469e6eb925b317c8469498508de4b7:922c64590222798bb761d5b6d8e72950