Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SMP unauthenticated access to SysAdminWebTool servlets, SAP security note 2227855

SAP Note 2227855
SAP Security Note
High priority

SAP security note 2227855, “SMP unauthenticated access to SysAdminWebTool servlets”, is a program error note released on 08.12.2015. Below are the symptom and SAP recommended solution.

ComponentBusiness Mobile > Sybase Unwired Platform > Sybase Control Center Administration
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on08.12.2015
LanguageEnglish

Description

Symptom

Some URLs on the SAP Control Center Admin UI for SMP 2.3 and the MBO support addon for SMP 3.0 had no access control policy assigned. This could result in denial of service attacks or compromise of data.

Solution

This is fixed in SAP Mobile Platform SP09 and SAP Mobile Server 2.3.7.

Reason and prerequisites

Some web services were added to the SCC server in ancillary support of some native functions of the UI like log uploads/downloads and application deployment. Normal usage would require a user to authenticate as a user in the Administrator role before they would navigate to use these services, but an attacker with network access to this server could bypass this normal usage.

CVSS

Score 6.8 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Full note on SAP: SAP Support Launchpad note 2227855

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More