Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Note Vulnerable DSM Terminator, SAP security note 1235253

SAP Note 1235253
HotNews

SAP security note 1235253, “Vulnerable DSM Terminator”, is an advanced development note released on October 8, 2009. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > SAP Enterprise Portal (On Premise) > Application Integration > Session Release Agent
CategoryAdvanced Development
PriorityHotNews
StatusReleased for Customer
Released onOctober 8, 2009

Description

Symptom

A security vulnerability has been identified in the portal’s DSM Terminator component when using Microsoft Internet Explorer. This issue may allow an attacker to take control of the client’s PC or steal the Single Sign-On (SSO) cookie. Currently, there is no workaround or mitigation available for this vulnerability. The only solution is to update to the fixed versions listed below.

Affected versions include NW04 SP22, NW04s SP14 Patch Level 2, NW04s SP15 Patch Level 2, NW04s SP16 Patch Level 1, and NW 7.1 SP6 and below.

Solution

The vulnerability is addressed in the following versions. It is recommended to apply the corresponding support package patches to mitigate the risk:

  • NW04 SP23
  • NW04s SP14 Patch Level 3
  • NW04s SP15 Patch Level 3
  • NW04s SP16 Patch Level 2
  • NW04s SP17
  • NW04s EhP1 (7.01) SP2 and above
  • NW 7.1 SP7 and above
  • NW 7.1 EhP1 (7.11) and above

Full note on SAP: SAP Support Launchpad note 1235253

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More