SAP security note 768454, “UME with ABAP persistence <= 6.10 allows logon without password”, is a note. Below are the symptom, reason and prerequisites, SAP recommended solution, CVSS score, references and the affected software components.
Description
Symptom
Users can log on to the SAP Enterprise Portal 6, the SAP J2EE Engine, or applications based on these platforms without entering a password.
Solution
The correction is available in the following releases:
- SAP Enterprise Portal 6 Support Package 2 Patch 4 Hotfix 8.
- SAP Enterprise Portal 6 Support Package 2 Patch 5.
- SAP NetWeaver 2004 Support Package Stack 04 (WebAS Java Support Package 7): an advance correction is provided as an attachment to this note.
- SAP NetWeaver 2004 Support Package Stack 05 (WebAS Java Support Package 8).
Reason and prerequisites
- The User Management Engine (UME) uses an ABAP back-end system with Release 6.10 or lower (e.g., R/3 4.6C) as a user storage system.
- This issue only affects users originating from the ABAP back-end system.
CVSS
Score 0
References
Affected components
- EP-PSERV (6.0)
- SAP-JEE (6.40)
Full note on SAP: SAP Support Launchpad note 768454
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
