SAP security note 1134621, "SAP NW Identity Management 7.0 SP1 Patch 1 (Security Patch)", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
The SAP NetWeaver Identity Management Identity Center PHP workflow UI has been found to be vulnerable to security issues that can allow attackers to gain unauthorized access rights to view and modify sensitive and critical Identity Center data.
Solution
These issues are resolved with Patch 1 for SAP NetWeaver Identity Management 7.0 SP1 Identity Center. It is strongly recommended to install this patch as soon as possible. You can download the patch from the Download for SNOTE or the PDF Version.
Additionally, it’s recommended to read and follow the new SAP NetWeaver Identity Management Security Guide, which summarizes the recommended security configurations from various installation documents. You can find the guide here: SAP NetWeaver Identity Management Security Guide.
References
- SAP NW Identity Management 7.0 SP1 Patch 2
- Japanese Installation of Identity Center 7.0 SP1
- Release Restrictions SAP NetWeaver Identity Management 7.0
Full note on SAP: SAP Support Launchpad note 1134621
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



