SAP security note 1590689, "PI SEC: HTTP verb tampering issue in AF Application". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
In the ‘Adapter Framework Application’, there are problems with authorization and authentication checks if certain HTTP methods are used.
An attacker can control the behavior of the system, or potentially escalate privileges by executing malicious code, without having legitimate credentials.
Solution
This issue is resolved with the referenced Support Packages and Patches of the Software Component XI ADAPTER FRAMEWORK (SAP_XIAF).
Reason and prerequisites
- Do not grant the role SAP_ungranted_role to any user.
- Ensure SAP Note 1445998 is applied to disable invokerservlet (Not required for NW 7.20 SP03 and above). While Verb-Tampering and InvokerServlet problems and solutions are not prerequisites of each other, it is recommended to apply both fixes.
References
This note refers to
- 1675853 – SAP EhP1 for XI on Netweaver 7.00 SP11
- 1666253 – NW04s XI Support Package Stack 26
- 1664303 – SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP09
- 1664301 – SAP Netweaver for PI 7.10 Support Package 14
- 1655997 – XI 30 Support Package Stack (SPS) 29
- 1649430 – SAP EhP2 for Netweaver 7.00 SP10
- 1445998 – Disabling invoker servlet
Referenced by
Affected components
- SAP_XIAF 3.0
- SAP_XIAF 7.00 to 7.02
- SAP_XIAF 7.10 to 7.11
- SAP_XIAF 7.20
- SAP_XIAF 7.30
- SAP_XIAF 7.31
Full note on SAP: SAP Support Launchpad note 1590689
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



