SAP security note 1533004, “Authentication bypass vulnerability in ESR”, released on November 8, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Some Java-based administration pages used in the ESR administration are vulnerable to authentication bypass. This can potentially result in an escalation of privileges. Furthermore, it can be exploited for remote file overwrite, denial of service attacks, user locking, and SMB relay attacks.
Solution
Apply the provided patch to ensure that each HTTP request undergoes the necessary authentication checks.
Reason and prerequisites
Certain HTTP requests bypass the authentication checks performed for HTTP GET requests, allowing commands to be executed without proper authentication. The affected Java Servlets and Java Server Pages belong to the old administration pages, which were replaced in NetWeaver 7.1 with a Web Dynpro-based solution. However, the old pages still exist and are accessible.
References
- SAP Note 1580663 – XI 30 Support Package Stack (SPS) 28
- SAP Note 1576121 – SAP EhP1 for XI on NetWeaver 7.00 SP09
- SAP Note 1570042 – ESR, SR, UDDI, Messaging related changes in 7.11 SP07
- SAP Note 1561929 – SAP EhP2 for NetWeaver 7.00 SP07
- SAP Note 1531912 – SAP EhP1 for XI on NetWeaver 7.00 SP08
- SAP Note 1459565 – SAP EHP1 for SAP NetWeaver PI 7.1 SP05
Affected components
- SAP_XITOOLS 6.40
- SAP_XITOOLS 7.00
- SAP_XITOOLS 7.01
- SAP_XITOOLS 7.02
- SAP_XIESR 7.10
- SAP_XIESR 7.11
- SAP_XIESR 7.20
- SAP_XIESR 7.30
- SAP_XIESR 7.31
Full note on SAP: SAP Support Launchpad note 1533004
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




