Skip links
🔥🔥🔥 Join us for our upcoming training session at Black Hat MEA: "Securing SAP Systems: Expert Insights and Penetration Testing Techniques" 🛡️🔍

Session Fixation Attack Detection, SAP security note 1417679

Description

The HTTP response is with response code 403 Forbidden and with default error message similar to the following:
“Possible session fixation attack detected! Contact your system administrator with a reference to SAP Note 1417679!”.

Available fix and Supported packages

  • ENGINEAPI | 7.10 | 7.11
  • ENGINEAPI | 7.20 | 7.20
  • LMNWABASICAPPS | 7.10 | 7.11
  • LMNWABASICAPPS | 7.20 | 7.20
  • SERVERCORE | 7.10 | 7.10
  • SERVERCORE | 7.11 | 7.11
  • SERVERCORE | 7.20 | 7.20
  • ENGINEAPI 7.10 | SP009 | 000008
  • ENGINEAPI 7.10 | SP010 | 000006
  • ENGINEAPI 7.11 | SP003 | 000010
  • ENGINEAPI 7.11 | SP004 | 000011
  • ENGINEAPI 7.20 | SP001 | 000007
  • ENGINEAPI 7.20 | SP002 | 000009
  • J2EE ENGINE SERVERCORE 7.10 | SP009 | 000021
  • J2EE ENGINE SERVERCORE 7.10 | SP010 | 000015
  • J2EE ENGINE SERVERCORE 7.10 | SP011 | 000000
  • J2EE ENGINE SERVERCORE 7.11 | SP003 | 000024
  • J2EE ENGINE SERVERCORE 7.11 | SP004 | 000019
  • J2EE ENGINE SERVERCORE 7.11 | SP005 | 000000
  • J2EE ENGINE SERVERCORE 7.20 | SP001 | 000011
  • J2EE ENGINE SERVERCORE 7.20 | SP002 | 000013
  • J2EE ENGINE SERVERCORE 7.20 | SP003 | 000000
  • LM NWA BASIC APPS 7.10 | SP009 | 000003
  • LM NWA BASIC APPS 7.10 | SP010 | 000002
  • LM NWA BASIC APPS 7.11 | SP003 | 000003
  • LM NWA BASIC APPS 7.11 | SP004 | 000004
  • LM NWA BASIC APPS 7.11 | SP005 | 000001

Affected component

    BC-JAS-SEC
    Security, User Management

CVSS

Score: 0

Exploit


Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1417679

Request more details about the vulnerability

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer