HotNews
SAP security note 1235253, “Vulnerable DSM Terminator”, is an advanced development note released on October 8, 2009. Below are the symptom and SAP recommended solution.
Description
Symptom
A security vulnerability has been identified in the portal’s DSM Terminator component when using Microsoft Internet Explorer. This issue may allow an attacker to take control of the client’s PC or steal the Single Sign-On (SSO) cookie. Currently, there is no workaround or mitigation available for this vulnerability. The only solution is to update to the fixed versions listed below.
Affected versions include NW04 SP22, NW04s SP14 Patch Level 2, NW04s SP15 Patch Level 2, NW04s SP16 Patch Level 1, and NW 7.1 SP6 and below.
Solution
The vulnerability is addressed in the following versions. It is recommended to apply the corresponding support package patches to mitigate the risk:
- NW04 SP23
- NW04s SP14 Patch Level 3
- NW04s SP15 Patch Level 3
- NW04s SP16 Patch Level 2
- NW04s SP17
- NW04s EhP1 (7.01) SP2 and above
- NW 7.1 SP7 and above
- NW 7.1 EhP1 (7.11) and above
Full note on SAP: SAP Support Launchpad note 1235253
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
