Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Insufficient length of session cookies of J2EE Engine, SAP security note 1425505

SAP Note 1425505
SAP Security Note
Medium priority

SAP security note 1425505, "Insufficient length of session cookies of J2EE Engine", is a program error note released on 09.02.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > NetWeaver Application Server Java > Web Container, HTTP, JavaMail, Servlets
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on09.02.2010
LanguageEnglish

Description

Symptom

sessionID cookies of the Engine are too short.

Solution

Upgrade the SAP J2EE Engine to the latest version. See section SP / Patch Level of the Note.

Reason and prerequisites

The session cookies generated by the Engine have been enhanced to include more random bits thus increasing security.

References

Affected components

  • SAP-JEECOR (7.00 to 7.00, 6.40 to 6.40, 7.01 to 7.02)

Full note on SAP: SAP Support Launchpad note 1425505

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More