Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Login Phishing Vulnerability of AS Java, SAP security note 1530827

SAP Note 1530827

SAP security note 1530827, "Login Phishing Vulnerability of AS Java", is a note. Below are the symptom, SAP recommended solution, CVSS details, references and the affected software components.

Description

Symptom

Prevent automatic logon with username and password within a single request.

Solution

The fix can be enabled by setting the UME property ume.logon.userpwd_automatic_logon to false.

The solution is available since:

  • 640 SP26
  • 700 SP22
  • 701 SP7
  • 702 SP3
  • 710 SP10
  • 711 SP5
  • 720 SP1
  • 730 SP0
  • 731 SP1

Important: This feature spreads over different components described in the “SP Patch level” tab. Deploying only one of them might cause problems with login.

For releases 702 and below, the global value of the property ume.logon.userpwd_automatic_logon needs to be modified.

Reason and prerequisites

A phishing security vulnerability has been mitigated. Data confidentiality might be compromised because the victim might not be aware they are performing a malicious request.

CVSS

Score 0

References

Affected components

  • EPBC2: 7.00 to 7.02
  • ENGINEAPI: 7.10 to 7.11, 7.20, 7.30, 7.31
  • EP-PSERV: 6.0_640
  • SAP-JEE: 6.40, 7.00 to 7.02
  • SAP_JTECHS: 6.40, 7.00 to 7.02
  • SAP-JEECOR: 7.00 to 7.02
  • SERVERCORE: 7.10 to 7.11, 7.20, 7.30, 7.31
  • J2EE-APPS: 7.10 to 7.11, 7.20, 7.30, 7.31

Full note on SAP: SAP Support Launchpad note 1530827

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More