SAP security note 1625314, “HTTP Verb Tampering Issue in BRMS-CORE”, is a note released on October 11, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BRMS-CORE has issues with authorization and authentication checks when certain HTTP methods are used. An attacker can potentially control system behavior or escalate privileges by executing malicious code without legitimate credentials.
Solution
Apply the appropriate patch matching your support package version as listed below, following the instructions in the NetWeaver Support Package Stack Guide.
Reason and prerequisites
BRMS-CORE contains HTTP verb tampering vulnerabilities, posing risks of information disclosure or data tampering via unexpected HTTP methods.
- "SAP_ungranted_role" shall never be granted to any user.
- Apply SAP Note 1445998 – Disabling invoker servlet (not required for NW 7.20 SP03 and above). It is recommended to apply both fixes for Verb-Tampering and InvokerServlet issues.
CVSS
Score 0
References
Affected components
- BRMS-CORE (versions 7.20, 7.30, 7.31)
Full note on SAP: SAP Support Launchpad note 1625314
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




