Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Leverage of privileges in ABAP Server of SAP NetWeaver and ABAP Platform, SAP security note 2748048

SAP Note 2748048

SAP security note 2748048, "Leverage of privileges in ABAP Server of SAP NetWeaver and ABAP Platform". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The ABAP Server fails to invalidate HTTP Security Sessions immediately upon user log-off.

HTTP Security Sessions do not time out automatically when an ABAP application server is stopped.

Solution

Implement at least the assigned kernel patch (disp+work package).

Reason and prerequisites

The Application Server ABAP system has more than one dialog instance. Buffering for the table SECURITY_CONTEXT is enabled (standard as of SAP_BASIS 7.50).

CVSS

Score 5.0

Affected components

  • KRNL32NUC (Versions: 7.21, 7.21EXT)
  • KRNL32UC (Versions: 7.21, 7.21EXT)
  • KRNL64NUC (Versions: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49)
  • KRNL64UC (Versions: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.73)
  • KERNEL (Versions: 7.21 to 7.73)

Full note on SAP: SAP Support Launchpad note 2748048

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More