SAP Security Note
Medium priority
SAP security note 1623895, "Missing authentication check in Usage Types Viewer", is a program error note released on 11.10.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An unauthorized user can use functions of the Usage Types Viewer (technical component com.sap.sl.ut.info), access to which should be restricted.
Solution
Apply the latest Support Package (SP) or patch of the NetWeaver Java component SAP_JTECHS for releases based on SAP NetWeaver 7.0 or LM-CORE for releases based on SAP NetWeaver 7.1 and higher, which contains a fix that completely removes the mentioned vulnerability. The fix is available in the following NetWeaver releases:
- SAP NetWeaver 7.0 SP26 (SAP_JTECHS)
- SAP NetWeaver 7.0 EHP1 SP11 (SAP_JTECHS)
- SAP NetWeaver 7.0 EHP2 SP10 (SAP_JTECHS)
- SAP NetWeaver PI/CE 7.1 SP14 (LM-CORE)
- SAP NetWeaver PI/CE 7.1 EHP1 SP09 (LM-CORE)
- SAP NetWeaver CE 7.2 SP07 (LM-CORE)
- SAP NetWeaver 7.3 SP05 (LM-CORE)
- SAP NetWeaver 7.3 EHP1 SP02 (LM-CORE)
The fix is also available in the latest patches of the following NetWeaver releases:
- SAP NetWeaver 7.0 SP22 to SP25 (SAP_JTECHS)
- SAP NetWeaver 7.0 EHP1 SP06 to SP10 (SAP_JTECHS)
- SAP NetWeaver 7.0 EHP2 SP03 to SP09 (SAP_JTECHS)
- SAP NetWeaver PI/CE 7.1 SP10 to SP13 (LM-CORE)
- SAP NetWeaver PI/CE 7.1 EHP1 SP05 to SP08 (LM-CORE)
- SAP NetWeaver CE 7.2 SP02 to SP06 (LM-CORE)
- SAP NetWeaver 7.3 SP01 to SP04 (LM-CORE)
- SAP NetWeaver 7.3 EHP1 SP00 to SP01 (LM-CORE)
We recommend that you apply in addition the SAP Note 1445998 to disable the invoker servlet. None of the two notes are prerequisites of each other.
Reason and prerequisites
The Usage Types Viewer application (technical component com.sap.sl.ut.info) is vulnerable to an attack which bypasses authentication checks for checking the identity and role of a user attempting to access its functions. This may result in an unauthorized user being able to retrieve information about the installed usage types and components in the system. As the Usage Types Viewer application does not provide any write capabilities, system availability and integrity are not endangered.
References
This note refers to
Affected components
- LM-CORE (7.10 to 7.11, 7.20, 7.30, 7.31)
- SAP_JTECHS (7.00 to 7.02)
Full note on SAP: SAP Support Launchpad note 1623895
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
