SAP security note 1624450, "Update #1 to Security Note 1589525". Below are the symptom and SAP recommended solution.
Description
Symptom
Patches provided for the verb tampering vulnerability addressed in Security Note 1589525 are re-released after further in-depth investigations. The patches for the following releases have been improved:
- 6.40
- 7.0x
- 7.10, 7.11, 7.20
- 7.30
Additionally, the manual implementation steps and workarounds have been clarified and enhanced. Note that the manual implementation steps are the preferred solution if you are unable to install the respective SP patch level.
Solution
- For customers who have already applied the SP patch level for the affected releases: Apply the respective SP patch level again.
- For customers who followed the manual implementation steps or applied one of the two workarounds: Revisit and perform them again. If you cannot apply the automatic Correction Instruction, we strongly recommend following the manual implementation steps.
- For customers who have not applied the patch, manual implementation steps, or workarounds: Apply the respective SP patch level or follow the manual implementation steps. If the first two alternatives are not possible, consider one of the two workarounds.
Reason and prerequisites
We have continued to diligently investigate the issue in depth and are now able to re-release improved patches for the releases 6.40, 7.0x, 7.10, 7.11, 7.20, and 7.30. We have also improved descriptions of the workarounds and manual implementation steps.
References
- 1889488 – Briefing at Black Hat conference on July 31st, 2013
- 1589525 – Verb Tampering issues in CTC
- 1740018 – Briefing at Black Hat conference on July 26th, 2012
Full note on SAP: SAP Support Launchpad note 1624450
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
