Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authentication bypass vulnerability in ESR, SAP security note 1533004

SAP Note 1533004

SAP security note 1533004, “Authentication bypass vulnerability in ESR”, released on November 8, 2011. Below are the symptom, SAP recommended solution and the affected software components.

Released onNovember 8, 2011

Description

Symptom

Some Java-based administration pages used in the ESR administration are vulnerable to authentication bypass. This can potentially result in an escalation of privileges. Furthermore, it can be exploited for remote file overwrite, denial of service attacks, user locking, and SMB relay attacks.

Solution

Apply the provided patch to ensure that each HTTP request undergoes the necessary authentication checks.

Reason and prerequisites

Certain HTTP requests bypass the authentication checks performed for HTTP GET requests, allowing commands to be executed without proper authentication. The affected Java Servlets and Java Server Pages belong to the old administration pages, which were replaced in NetWeaver 7.1 with a Web Dynpro-based solution. However, the old pages still exist and are accessible.

References

Affected components

  • SAP_XITOOLS 6.40
  • SAP_XITOOLS 7.00
  • SAP_XITOOLS 7.01
  • SAP_XITOOLS 7.02
  • SAP_XIESR 7.10
  • SAP_XIESR 7.11
  • SAP_XIESR 7.20
  • SAP_XIESR 7.30
  • SAP_XIESR 7.31

Full note on SAP: SAP Support Launchpad note 1533004

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More