SAP security note 694681, "Security gaps in the SAP Internet Transaction Server". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
In December 2003, several security gaps were discovered in the SAP Internet Transaction Server (ITS) and published at the Chaos Computer Club conference at the end of December.
Solution
The security gaps mentioned above have been closed using the following SAP ITS patches:
- ITS 4.6DC4: Patch level 463 or higher.
- ITS 6.10: Patch level 30 or higher.
- ITS 6.20: Patch level 7 or higher.
Since SAP ITS 4.6DC4 is no longer maintained as of January 01, 2004, you should immediately upgrade all installations based on Release ITS 4.6DC4 or lower to ITS Release 6.20 or 6.10 with the minimum patch levels specified above. If you are already using ITS 4.6DC4 with patch level 464, you can continue to use this without risk. However, it is recommended to carry out a release upgrade because no further corrections will be made in Release 4.6DC4.
It is strongly recommended to install one of the specified patches or a higher patch.
References
- 678523 – Security: buffer overrun, random numbers, ~session cookie
- 598074 – No fullpath leakage to end-user.
Affected components
- BC-FES-ITS: From 46D C4 to 46D C4
- BC-FES-ITS: From 610 to 620
Full note on SAP: SAP Support Launchpad note 694681
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




