Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Improper Session Management in ABAP Server of SAP NetWeaver and ABAP Platform, SAP security note 2748063

SAP Note 2748063

SAP security note 2748063, "Improper Session Management in ABAP Server of SAP NetWeaver and ABAP Platform". Below are the symptom and the SAP recommended solution.

Description

Symptom

Under certain circumstances, the ABAP Server of SAP NetWeaver and ABAP Platform does not delete the HTTP Security Session cookie from the browser, even after the HTTP Security Session has been invalidated. This can allow access to the session cookie via a local browser, enabling an attacker to leverage the privileges of another user. The level of privileges obtained depends on the user whose session cookies are accessed.

Solution

Apply the relevant Support Package or the attached correction instruction.

Reason and prerequisites

The Application Server ABAP system has more than one dialog instance. Buffering for table SECURITY_CONTEXT is enabled (standard as of SAP_BASIS 7.50).

CVSS

Score 3.7 Vector: CVSS:3.0/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2748063

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More