SAP security note 1561103, "Java Runtime lacks appropriate authorizations". Below are the symptom, reason and prerequisites and SAP recommended solution.
Description
Symptom
Oracle recently issued a security alert for the Java Runtime Environment, which leads to the Java Runtime Environment lacking appropriate authorizations under certain circumstances. SAP products using SAP JVM are also affected by the same vulnerabilities.
Solution
Please apply the patch level mentioned in this note at least.
Reason and prerequisites
SAP JVM does not contain authorization checks for checking an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.
Full note on SAP: SAP Support Launchpad note 1561103
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




