SAP security note 1467771, "Disabling invoker servlet in the portal". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Once disabling the default servlet mapping /servlet/* by changing the value of the EnableInvokerServletGlobally property of the servlet_jsp service on the server nodes to false, the portal becomes inaccessible.
Solution
A fix is available for the following versions:
- SAP NetWeaver 6.40: SP23 Latest Patch, SP24 Latest Patch, SP25 Latest Patch, SP26 Latest Patch, SP27 and above
- SAP NetWeaver 7.00: SP18 Latest Patch, SP19 Latest Patch, SP20 Latest Patch, SP21 Latest Patch, SP22 and above
- SAP NetWeaver 7.01: SP03 Latest Patch, SP04 Latest Patch, SP05 Latest Patch, SP06 Latest Patch, SP07 and above
- SAP NetWeaver 7.02: SP03 Latest Patch, SP04 and above
- SAP NetWeaver CE 7.10: SP07 Latest Patch, SP08 Latest Patch, SP09 Latest Patch, SP10 and above
- SAP NetWeaver CE 7.11: SP03 Latest Patch, SP04 Latest Patch, SP05 and above
- SAP NetWeaver CE 7.20: SP01 Latest Patch, SP02 Latest Patch, SP03 and above
- SAP NetWeaver 7.30: SP02 and above
Reason and prerequisites
Affected Products: SAP NetWeaver Portal 6.40 and above
References
- 1616259 – Briefing at Black Hat conference on August 4th, 2011
- 1598246 – Servlet declaration missing for LWC SOAP Dispatcher servlet
- 1537663 – Biller Direct, Security – Invoker Servlet
- 1511415 – Disabling Invoker Servlet in Tomcat
- 1488846 – CRM ECO. Security – Invoker Servlet
- 1445998 – Disabling invoker servlet
Full note on SAP: SAP Support Launchpad note 1467771
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



