Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in password telnet command, SAP security note 1776718

SAP Note 1776718
High priority

SAP security note 1776718, "Missing authorization check in password telnet command", is a note released on December 10, 2013. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Security, User Management (BC-JAS-SEC)
PriorityHigh priority
StatusReleased for Customer
Released onDecember 10, 2013

Description

Symptom

An authenticated user can use functions of the password telnet command to which access should be restricted. This may result in an escalation of privileges.

Solution

Update your Java AS to a Support Package (SP) or release where the issue is resolved.

Reason and prerequisites

The password telnet command does not include authorization checks to verify an authenticated user’s permissions for accessing certain functions. This oversight can lead to undesired system behavior and potential privilege escalation.

Full note on SAP: SAP Support Launchpad note 1776718

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More