Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential runtime problems after manipulation of isa_relogin, SAP security note 1626152

SAP Note 1626152

SAP security note 1626152, "Potential runtime problems after manipulation of isa_relogin". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

For CRM Web Channel B2B and B2C applications, the isa_relogin cookie allows users to log on to a Web shop again after losing a Web session.

If the cookie content in the HTTP request does not match the required format, a runtime error may occur.

Solution

This SAP Note contains Java corrections for E-Commerce and CRM Web Channel. Apply the Support Package patch level specified in this SAP Note.

Reason and prerequisites

The content of the isa_relogin cookie can be manipulated in such a way that a runtime error occurs when the cookie is evaluated.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N

References

Affected components

  • CRM JAVA APPLICATIONS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
  • SAP SHARED JAVA COMPONENTS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
  • CRM JAVA COMPONENTS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
  • CRM JAVA WEB COMPONENTS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
  • SAP SHARED WEB COMPONENTS: 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.32
  • SAP-SHRWEB, SAP-SHRJAV, SAP-CRMAPP, SAP-SHRAPP: various versions as listed in the note

Full note on SAP: SAP Support Launchpad note 1626152

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More