Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update 2 to security note 1651004, SAP security note 1839511

SAP Note 1839511
High priority

SAP security note 1839511, "Update 2 to security note 1651004," is a note released on 28.03.2013. Below are the symptom and the SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Security, User Management
PriorityHigh priority
StatusReleased for Customer
Released on28.03.2013

Description

Symptom

Security note 1651004 has been rereleased due to missing validity entries. Newly added releases that are affected are listed below:

  • SAP J2EE ENGINE 640 SP26, SP27, SP28, SP29
  • SAP J2EE ENGINE 700 SP23, SP24, SP25, SP26
  • SAP J2EE ENGINE 701 SP07, SP08, SP09, SP10
  • SAP J2EE ENGINE 702 SP05, SP06, SP07, SP08, SP09, SP10
  • PORTAL PLATFORM 6.0_640 SP26, SP27, SP28, SP29
  • SAP J2EE ENGINE CORE 700 SP23, SP24, SP25, SP26
  • SAP J2EE ENGINE CORE 701 SP07, SP08, SP09, SP10
  • SAP J2EE ENGINE CORE 702 SP05, SP06, SP07, SP08, SP09, SP10
  • SAP JAVA TECH SERVICES 700 SP23, SP24, SP25, SP26
  • SAP JAVA TECH SERVICES 701 SP07, SP08, SP09, SP10
  • SAP JAVA TECH SERVICES 702 SP05, SP06, SP07, SP08, SP09, SP10
  • PORTAL FRAMEWORK 700 SP23, SP24, SP25, SP26
  • PORTAL FRAMEWORK 701 SP07, SP08, SP09, SP10
  • PORTAL FRAMEWORK 702 SP05, SP06, SP07, SP08, SP09, SP10

Solution

There are no special steps to be performed. Note 1651004 has already been updated with the correct entries, so when applying it, you don’t need to do any additional work.

Reason and prerequisites

The validity of security note 1651004 has been extended with further affected releases.

References

Full note on SAP: SAP Support Launchpad note 1839511

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More