Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Note Vulnerable Parameters Passing in AI, SAP security note 1241503

SAP Note 1241503
SAP Security Note
High priority

SAP security note 1241503, "Security Note: Vulnerable Parameters Passing in AI", was released on 20.07.2010. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > SAP Enterprise Portal (On Premise) > Application Integration
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on20.07.2010

Description

Symptom

Security Note: A security issue was found when running BSP iView using ‘User Mapping’ Authentication.

The security issue may allow an attacker to see the parameters passed to the backend.

There is no workaround for this issue except installing the versions described in the solution section. Additionally, there are no mitigations available.

Solution

NW04 SP23 and above.

Reason and prerequisites

NW04 SP22 and below.

Full note on SAP: SAP Support Launchpad note 1241503

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More