SAP security note 1782955, "Missing authorization check in the telnet command password". Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use the password telnet command, to which access should be restricted. This may result in exceeding user privileges.
Solution
Update your Java AS to a Support Package (SP) or release where the issue is fixed. See the Support Package Patch Level section for details and available patches.
Reason and prerequisites
The password telnet command does not contain authorization checks for an authenticated user. This may result in undesired system behavior.
Full note on SAP: SAP Support Launchpad note 1782955
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
