SAP Security Note
High priority
SAP security note 1569773, "Security sessions might remain alive after expiration period", is a program error note released on 13.09.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
In some scenarios, HTTP application sessions might remain alive after the expiration of a security session. This might result in an extended window for attack by a malicious user who has somehow managed to get access to the session cookies, e.g., by XSS or another attack.
Solution
Update AS Java to the latest patch level of the SP mentioned in the SP Patch Level section.
Reason and prerequisites
Due to a program error in session management, it is possible that a security session might not be invalidated after its expiration.
CVSS
Score 0
References
- 1623364 – SAP NetWeaver AS Java 7.11 SP8 List of corrections
- 1623301 – SAP NetWeaver AS Java 7.10 SP13 List of corrections
- 1601417 – NullPointerException in Web Services Navigator
Affected components
- ENGINEAPI: 7.10 to 7.11
- ENGINEAPI: 7.20
- ENGINEAPI: 7.30
- SERVERCORE: 7.10
- SERVERCORE: 7.11
- SERVERCORE: 7.20
- SERVERCORE: 7.30
Full note on SAP: SAP Support Launchpad note 1569773
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
