Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Issues in SAML 1.1 Browser/Artifact Profile, SAP security note 1541765

SAP Note 1541765

SAP security note 1541765, "Security Issues in SAML 1.1 Browser/Artifact Profile", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

This SAP Security Note addresses several security vulnerabilities in the SAML 1.1 Browser/Artifact Profile implementation within the AS Java environment. The affected web applications include "SAML SSO Demo Application" and "SAML SSO Application". The key issues are:

Unauthorized Modification of Displayed Content. Malicious users can modify application content without authorization, potentially stealing authentication information from other users.

Unauthorized Use of Application Functions. Certain functions can be executed without proper authentication and authorization, allowing malicious users to perform unauthorized actions.

Escalation of Privileges. Authenticated users can gain access to other users’ applications and privileges through the SAML SSO Demo Application.

Potential False Redirection of Website Content. Enables phishing attacks by redirecting users to malicious sites, tricking them into revealing sensitive information.

Solution

  • Install the Relevant Support Package. Apply the support package listed in this SAP Note to address the identified vulnerabilities.
  • Immediate Countermeasure: Disable the SAML SSO Demo Application.
    • For NetWeaver 7.10 and Higher: Navigate to ConfigTool, switch to "Expert Mode", go to "Filters", and set Action to "Disable", Component to "application", Vendor Mask to "sap.com", and Component Name Mask to "tc~sec~saml~ssodemoapp".
    • For SAP NetWeaver 6.40 and 7.0x: Ensure the SAML Service is not started by checking in Visual Administrator under "Services" → "SAML". If using SAML, disable the demo application by removing all login modules in the Policy Configurations for "sap.com/tc~sec~app*samlssodemo_source".

References

Full note on SAP: SAP Support Launchpad note 1541765

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More