SAP Security Note
High priority
SAP security note 1831932, "Missing authentication in AS2 Adapter", is a program error note released on 10.09.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can execute functions in B2B AS2 Adapters without authentication.
Solution
This is fixed with the Support Packages and Patches of the Software Components referenced by this note in the section 'SP Patch Level'.
Reason and prerequisites
The vulnerability is caused by missing standard authentication and single sign-on mechanisms in a Java web servlet.
CVSS
Score 7.5 Vector: AV:N/AC:L/AU:N/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1831932
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
