Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security note HTTP request check tightened, SAP security note 1170848

SAP Note 1170848

SAP security note 1170848, "Security note: HTTP request check tightened", is a note. Below are the symptom and the SAP recommended solution.

Description

Symptom

In certain circumstances, specially crafted HTTP requests may lead to incorrect processing of requests in the backend.

Solution

The HTTP parser has been modified in the specified patch levels to recognize invalid requests at the kernel level, ensuring they are intercepted before reaching higher protocol layers. Apply the updates to the following kernel patch levels:

  • 711 kernel patch level: 0
  • 710 kernel patch level: 108
  • 701 kernel patch level: 8
  • 700 kernel patch level: 164
  • 640 kernel patch level: 237

Reason and prerequisites

The system sends specially prepared HTTP requests to the application server while using an older kernel version. An attacker can exploit these security gaps to evade the filter functions of the ICM and SAP Web Dispatcher. However, the application server remains secure if third-party products for URL filtering are employed.

References

Full note on SAP: SAP Support Launchpad note 1170848

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More