SAP Security Note
Medium priority
SAP security note 1425505, "Insufficient length of session cookies of J2EE Engine", is a program error note released on 09.02.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
sessionID cookies of the Engine are too short.
Solution
Upgrade the SAP J2EE Engine to the latest version. See section SP / Patch Level of the Note.
Reason and prerequisites
The session cookies generated by the Engine have been enhanced to include more random bits thus increasing security.
References
Affected components
- SAP-JEECOR (7.00 to 7.00, 6.40 to 6.40, 7.01 to 7.02)
Full note on SAP: SAP Support Launchpad note 1425505
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
