Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

PI SEC HTTP verb tampering issue in AF Application, SAP security note 1590689

SAP Note 1590689

SAP security note 1590689, "PI SEC: HTTP verb tampering issue in AF Application". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

In the ‘Adapter Framework Application’, there are problems with authorization and authentication checks if certain HTTP methods are used.

An attacker can control the behavior of the system, or potentially escalate privileges by executing malicious code, without having legitimate credentials.

Solution

This issue is resolved with the referenced Support Packages and Patches of the Software Component XI ADAPTER FRAMEWORK (SAP_XIAF).

Reason and prerequisites

  • Do not grant the role SAP_ungranted_role to any user.
  • Ensure SAP Note 1445998 is applied to disable invokerservlet (Not required for NW 7.20 SP03 and above). While Verb-Tampering and InvokerServlet problems and solutions are not prerequisites of each other, it is recommended to apply both fixes.

References

Affected components

  • SAP_XIAF 3.0
  • SAP_XIAF 7.00 to 7.02
  • SAP_XIAF 7.10 to 7.11
  • SAP_XIAF 7.20
  • SAP_XIAF 7.30
  • SAP_XIAF 7.31

Full note on SAP: SAP Support Launchpad note 1590689

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More