Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update #1 to Security Note 1511462, SAP security note 1604636

SAP Note 1604636
SAP Security Note
High priority

SAP security note 1604636, "Update #1 to Security Note 1511462", is a program error note released on October 12, 2011. Below are the symptom and the SAP recommended solution.

CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onOctober 12, 2011

Description

Symptom

A vulnerability allows a malicious user to trigger functionality in the SRM Java Tool Box without proper authentication and authorization. This update addresses the vulnerability outlined in Security Note 1511462 for the following Support Package Patch Level: SP10 for SRM JAVATOOLBOX 7.0.

Solution

You can locate SRM Java Tool Box 7.0 in the Support Package and Patch Area of the Service Marketplace.

Reason and prerequisites

Additional information for the Support Package Patch Level has been added to Security Note 1511462. The reference to "SRM 7.01 SP03" has been removed from the solution section of Note 1511462.

References

Full note on SAP: SAP Support Launchpad note 1604636

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More