SAP security note 1626152, "Potential runtime problems after manipulation of isa_relogin". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
For CRM Web Channel B2B and B2C applications, the isa_relogin cookie allows users to log on to a Web shop again after losing a Web session.
If the cookie content in the HTTP request does not match the required format, a runtime error may occur.
Solution
This SAP Note contains Java corrections for E-Commerce and CRM Web Channel. Apply the Support Package patch level specified in this SAP Note.
Reason and prerequisites
The content of the isa_relogin cookie can be manipulated in such a way that a runtime error occurs when the cookie is evaluated.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
References
- SAP Note 1546959 – Patch strategies for SAP E-Commerce solutions
- SAP Note 877887 – Installing Patches for CRM Java Components and FSCM BD
Affected components
- CRM JAVA APPLICATIONS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
- SAP SHARED JAVA COMPONENTS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
- CRM JAVA COMPONENTS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
- CRM JAVA WEB COMPONENTS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
- SAP SHARED WEB COMPONENTS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
- SAP-SHRWEB, SAP-SHRJAV, SAP-CRMAPP, SAP-SHRAPP: various versions as listed in the note
Full note on SAP: SAP Support Launchpad note 1626152
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
