SAP Security Note
High priority
SAP security note 1617369, “Verb Tampering issues in CMS”, is a program error note released on October 11, 2011. Below are the symptom, SAP recommended solution, references and the affected software components.
Description
Symptom
There are potential issues with authorization and authentication checks related to different HTTP methods used in the CMS (Change Management Service) of NWDI (NetWeaver Development Infrastructure).
Solution
Apply the patch attached to this note that matches the release and Support Package (SP) level of your AS Java hosting CMS.
Reason and prerequisites
CMS may have Verb Tampering vulnerabilities, which can lead to information disclosure and/or data tampering if accessed with HTTP requests containing unexpected HTTP methods. To mitigate this risk, apply SAP Note 1445998 to disable invokerservlet. Apply both SAP Notes 1617369 and 1445998 to ensure full protection against attacks through servlets of this component. Neither of these notes are strict prerequisites for each other, but both must be applied for complete protection.
References
Affected components
- DI_CMS 7.00 to 7.31
- SAP_DEVINF 6.40
Full note on SAP: SAP Support Launchpad note 1617369
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




