SAP security note 1942592, "ICM Check of Certificates Forwarded by Intermediary", is a program error note released on February 11, 2014. Below are the symptom and SAP recommended solution.
Description
Symptom
ICM accepts forwarded requests from intermediaries when either the subject or issuer of the client certificate matches.
Solution
Apply at least the patch level specified in the “SP Patch Level” section of the note to ensure that ICM only accepts certificates where both the subject and the issuer match.
Reason and prerequisites
This issue occurs when certificate forwarding is configured in the ICM of your application server using the parameters icm/HTTPS/trust_client_with_subject and icm/HTTPS/trust_client_with_issuer.
Without this fix, ICM accepts certificates if either the subject or the issuer matches, which may not meet the desired security criteria.
Full note on SAP: SAP Support Launchpad note 1942592
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
