Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

HTTP verb tampering issue in BRMS-CORE, SAP security note 1625314

SAP Note 1625314SAP Security NoteHigh priority

SAP security note 1625314, “HTTP Verb Tampering Issue in BRMS-CORE”, is a note released on October 11, 2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Business Management > Business Rules Management > Rules Engine (BC-BMT-BRM-ENG)
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onOctober 11, 2011
LanguageEnglish

Description

Symptom

BRMS-CORE has issues with authorization and authentication checks when certain HTTP methods are used. An attacker can potentially control system behavior or escalate privileges by executing malicious code without legitimate credentials.

Solution

Apply the appropriate patch matching your support package version as listed below, following the instructions in the NetWeaver Support Package Stack Guide.

Reason and prerequisites

BRMS-CORE contains HTTP verb tampering vulnerabilities, posing risks of information disclosure or data tampering via unexpected HTTP methods.

  • "SAP_ungranted_role" shall never be granted to any user.
  • Apply SAP Note 1445998 – Disabling invoker servlet (not required for NW 7.20 SP03 and above). It is recommended to apply both fixes for Verb-Tampering and InvokerServlet issues.

CVSS

Score 0

References

Affected components

  • BRMS-CORE (versions 7.20, 7.30, 7.31)

Full note on SAP: SAP Support Launchpad note 1625314

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More