Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authentication check in Usage Types Viewer, SAP security note 1623895

SAP Note 1623895
SAP Security Note
Medium priority

SAP security note 1623895, "Missing authentication check in Usage Types Viewer", is a program error note released on 11.10.2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Upgrade – general > Upgrade Tools (SUM) > Upgrade tools for Java (BC-UPG-TLS-TLJ)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on11.10.2011
LanguageEnglish

Description

Symptom

An unauthorized user can use functions of the Usage Types Viewer (technical component com.sap.sl.ut.info), access to which should be restricted.

Solution

Apply the latest Support Package (SP) or patch of the NetWeaver Java component SAP_JTECHS for releases based on SAP NetWeaver 7.0 or LM-CORE for releases based on SAP NetWeaver 7.1 and higher, which contains a fix that completely removes the mentioned vulnerability. The fix is available in the following NetWeaver releases:

  • SAP NetWeaver 7.0 SP26 (SAP_JTECHS)
  • SAP NetWeaver 7.0 EHP1 SP11 (SAP_JTECHS)
  • SAP NetWeaver 7.0 EHP2 SP10 (SAP_JTECHS)
  • SAP NetWeaver PI/CE 7.1 SP14 (LM-CORE)
  • SAP NetWeaver PI/CE 7.1 EHP1 SP09 (LM-CORE)
  • SAP NetWeaver CE 7.2 SP07 (LM-CORE)
  • SAP NetWeaver 7.3 SP05 (LM-CORE)
  • SAP NetWeaver 7.3 EHP1 SP02 (LM-CORE)

The fix is also available in the latest patches of the following NetWeaver releases:

  • SAP NetWeaver 7.0 SP22 to SP25 (SAP_JTECHS)
  • SAP NetWeaver 7.0 EHP1 SP06 to SP10 (SAP_JTECHS)
  • SAP NetWeaver 7.0 EHP2 SP03 to SP09 (SAP_JTECHS)
  • SAP NetWeaver PI/CE 7.1 SP10 to SP13 (LM-CORE)
  • SAP NetWeaver PI/CE 7.1 EHP1 SP05 to SP08 (LM-CORE)
  • SAP NetWeaver CE 7.2 SP02 to SP06 (LM-CORE)
  • SAP NetWeaver 7.3 SP01 to SP04 (LM-CORE)
  • SAP NetWeaver 7.3 EHP1 SP00 to SP01 (LM-CORE)

We recommend that you apply in addition the SAP Note 1445998 to disable the invoker servlet. None of the two notes are prerequisites of each other.

Reason and prerequisites

The Usage Types Viewer application (technical component com.sap.sl.ut.info) is vulnerable to an attack which bypasses authentication checks for checking the identity and role of a user attempting to access its functions. This may result in an unauthorized user being able to retrieve information about the installed usage types and components in the system. As the Usage Types Viewer application does not provide any write capabilities, system availability and integrity are not endangered.

References

Affected components

  • LM-CORE (7.10 to 7.11, 7.20, 7.30, 7.31)
  • SAP_JTECHS (7.00 to 7.02)

Full note on SAP: SAP Support Launchpad note 1623895

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More