Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Disabling invoker servlet in the portal, SAP security note 1467771

SAP Note 1467771

SAP security note 1467771, "Disabling invoker servlet in the portal". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Once disabling the default servlet mapping /servlet/* by changing the value of the EnableInvokerServletGlobally property of the servlet_jsp service on the server nodes to false, the portal becomes inaccessible.

Solution

A fix is available for the following versions:

  • SAP NetWeaver 6.40: SP23 Latest Patch, SP24 Latest Patch, SP25 Latest Patch, SP26 Latest Patch, SP27 and above
  • SAP NetWeaver 7.00: SP18 Latest Patch, SP19 Latest Patch, SP20 Latest Patch, SP21 Latest Patch, SP22 and above
  • SAP NetWeaver 7.01: SP03 Latest Patch, SP04 Latest Patch, SP05 Latest Patch, SP06 Latest Patch, SP07 and above
  • SAP NetWeaver 7.02: SP03 Latest Patch, SP04 and above
  • SAP NetWeaver CE 7.10: SP07 Latest Patch, SP08 Latest Patch, SP09 Latest Patch, SP10 and above
  • SAP NetWeaver CE 7.11: SP03 Latest Patch, SP04 Latest Patch, SP05 and above
  • SAP NetWeaver CE 7.20: SP01 Latest Patch, SP02 Latest Patch, SP03 and above
  • SAP NetWeaver 7.30: SP02 and above

Reason and prerequisites

Affected Products: SAP NetWeaver Portal 6.40 and above

References

Full note on SAP: SAP Support Launchpad note 1467771

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More