SAP Security Note
Low priority
SAP security note 1484557, “Determining HTTP log using ticket log parameters”, is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The class method cl_http_server=>get_location determines the log without considering the profile parameter login/ticket_only_by_https.
Solution
Import the current Support Package or implement the correction instructions.
Reason and prerequisites
This problem is caused by incorrect source code.
CVSS
Score 0
References
- 1531399 – Enabling SSL for Session Protection
- 1503491 – BSP CONSTRUCT_BSP_URL when ticket_only_by_https
Affected components
- SAP_BASIS 620 to 640
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 730
- SAP_BASIS 72L
Full note on SAP: SAP Support Launchpad note 1484557
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
