SAP Security Note
High priority
SAP security note 2227855, “SMP unauthenticated access to SysAdminWebTool servlets”, is a program error note released on 08.12.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
Some URLs on the SAP Control Center Admin UI for SMP 2.3 and the MBO support addon for SMP 3.0 had no access control policy assigned. This could result in denial of service attacks or compromise of data.
Solution
This is fixed in SAP Mobile Platform SP09 and SAP Mobile Server 2.3.7.
Reason and prerequisites
Some web services were added to the SCC server in ancillary support of some native functions of the UI like log uploads/downloads and application deployment. Normal usage would require a user to authenticate as a user in the Administrator role before they would navigate to use these services, but an attacker with network access to this server could bypass this normal usage.
CVSS
Score 6.8 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 2227855
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
