SAP Security Note
High priority
SAP security note 1642024, "Update #1 to Security Note 1462328", is released on 08.11.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
The solution for vulnerability "Unauthorized modification of stored content in HTMLB Java" given with Security Note 1462328 is additionally provided for the following SP Patch Levels: SAP JAVA TECH SERVICES 7.00 SP22
Solution
The issue described above will be fixed by an HTMLB for Java patch. In the section "SP Patch Level," you can find information about which patches contain the respective correction. Please install this patch or a newer one (HTMLB patches are always cumulative).
Downloading HTMLB for Java Patches
All HTMLB for Java patches are available on the SAP Service Marketplace.
Release Specific:
- NW04S / NW 7.00 / NW04S Ehp1 / NW 7.01 / NW04S Ehp2 / NW 7.02: The patch for this release will be an SCA. Deploy the SCA directly using SDM. Recommendation for Portal Usage: in the "SP Patch Level" tab, please apply the relevant EPBC2.SCA which is available in the service marketplace. Recommendation for Portal Independent Usage: in the "SP Patch Level" tab, please apply the relevant SAPJTECHS.SCA which is available in the service marketplace.
- NW07 / NW 7.10 / NW07 Ehp1 / NW 7.11: The patch for this release will be an SCA. Deploy the SCA directly using SDM. Recommendation for Portal Usage: in the "SP Patch Level" tab, please apply the relevant EPBASIS.SCA which is available in the service marketplace. Recommendation for Portal Independent Usage: in the "SP Patch Level" tab, please apply the relevant FRAMEWORK.SCA which is available in the service marketplace.
Note: Due to the fact that many of the SDAs included in the SCA are offline deployments, the engine is restarted during the deployment. An update is only required on the engine.
Time required: The required time depends on whether the engine has to be restarted. Additionally, the time required for the restart is determined by the applications installed on the engine.
Reason and prerequisites
Additional solutions for further SP Patch Levels should be added to Security Note 1462328.
References
Full note on SAP: SAP Support Launchpad note 1642024
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
