Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to EPCM data bag, SAP security note 1816989

SAP Note 1816989
SAP Security Note
Medium priority

SAP security note 1816989, “Potential information disclosure relating to EPCM data bag”, is a program error note released on 11.06.2013. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > SAP Enterprise Portal (On Premise) > Client Services
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on11.06.2013
LanguageEnglish

Description

Symptom

An attacker can discover information relating to “SAPPORTALSDB0” that is used in the portal EPCM client data bag. This information could be used to allow the attacker to specialize their attacks against the component that has used this client data bag cookie.

Solution

Please refer to the SP Patch level link to view the versions including the fix.

To enforce secure data bag (SAPPORTALSDB0) cookie:

  • Navigate to System Administration > Service Configuration (for NW: use SAP NetWeaver Administrator).
  • Access the following portal application and service: Application com.sap.portal.epcf.loader, Service epcfloader.
  • Set the com.sap.portal.epcf.databag.enforce_secure_cookie property value to true. This ensures that the client browser sends the cookie only when an SSL connection to the J2EE Engine or the reverse proxy is established. The default value is false.
  • Save your changes and restart the service.

Reason and prerequisites

Information that is stored by any application that is using this EPCM client data bag can be passed on a non-secure connection. This information may be used by an attacker to further target the application that is using this framework in the portal.

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 1816989

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More