SAP Security Note
HotNews
SAP security note 1499704, "KM security improvement for SSL Client Certificate checks", is a note released on January 10, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The user might not be properly validated against client certificate when using SSL communication.
Solution
A) Issue is resolved in the following releases: Please see the “SP Patch Level” tab in the current note for available releases.
B) Possible workaround: No.
Reason and prerequisites
The user’s client certificate might not be taken into account in some cases.
References
- 1755857 – Portal Runtime error appears when using KM Flex UI
- 1494028 – KMC in SAP EHP2 for SAP NetWeaver 7.0 SPS06
- 1428100 – KMC in SAP EHP2 for SAP NetWeaver 7.0 SPS04
Affected components
- EPBC2 7.00 to 7.02
- KMC-CM 7.00 to 7.02, 7.30, 7.31
- EP-CM 6.0_640
Full note on SAP: SAP Support Launchpad note 1499704
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
