SAP security note 1174895, "HTTP Request Smuggling problems solved", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Specially prepared HTTP requests or content length headers may lead to an incorrect processing of this request in the back end. (HTTP Request Smuggling)
Solution
The following patch levels modify the HTTP parser so that requests are recognized as invalid when reading and parsing the request at the kernel level, ensuring they are caught before being forwarded to higher protocol layers.
- 6.40: SP237
- 7.00: SP164
- 7.01: SP8
- 7.10: SP108
References
Affected components
- SAP_BASIS versions 6.40, 7.00, 7.01, and 7.10
Full note on SAP: SAP Support Launchpad note 1174895
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



