SAP Security Note
High priority
SAP security note 1620411, “Verb Tampering issues in UMEADMIN”, is a program error note released on 11.10.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Problems with authorization and authentication checks in conjunction with different HTTP methods used might exist in UMEADMIN.
Solution
Update AS Java to the latest version. For more information, see the SP Patch Level section of this SAP Note.
Reason and prerequisites
UMEADMIN might contain Verb Tampering vulnerabilities. This means that there is a risk of information disclosure and/or data tampering if the application is accessed with HTTP requests containing unexpected HTTP methods.
Full note on SAP: SAP Support Launchpad note 1620411
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



