SAP security note 908147, "Security Relevant Correction (HTTP Response Serialization)", is released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
This correction addresses a security weakness involving certain types of invalid or manipulated HTTP response messages.
Solution
The correction enhances security against specific manipulated or invalid HTTP response messages and is supplied via kernel patches for the following SAP kernel releases:
- 6.40: Patch Level 105
- 7.00: Patch Level 39
CVSS
Score 0
References
Full note on SAP: SAP Support Launchpad note 908147
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



