SAP security note 2748063, "Improper Session Management in ABAP Server of SAP NetWeaver and ABAP Platform". Below are the symptom and the SAP recommended solution.
Description
Symptom
Under certain circumstances, the ABAP Server of SAP NetWeaver and ABAP Platform does not delete the HTTP Security Session cookie from the browser, even after the HTTP Security Session has been invalidated. This can allow access to the session cookie via a local browser, enabling an attacker to leverage the privileges of another user. The level of privileges obtained depends on the user whose session cookies are accessed.
Solution
Apply the relevant Support Package or the attached correction instruction.
Reason and prerequisites
The Application Server ABAP system has more than one dialog instance. Buffering for table SECURITY_CONTEXT is enabled (standard as of SAP_BASIS 7.50).
CVSS
Score 3.7 Vector: CVSS:3.0/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2748063
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



