SAP Security Note
High priority
SAP security note 1241503, "Security Note: Vulnerable Parameters Passing in AI", was released on 20.07.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
Security Note: A security issue was found when running BSP iView using ‘User Mapping’ Authentication.
The security issue may allow an attacker to see the parameters passed to the backend.
There is no workaround for this issue except installing the versions described in the solution section. Additionally, there are no mitigations available.
Solution
NW04 SP23 and above.
Reason and prerequisites
NW04 SP22 and below.
Full note on SAP: SAP Support Launchpad note 1241503
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
