SAP security note 1846438, "Unauthorized use of application functions in AS Java", is a program error note released on 11.02.2014. Below are the symptom, SAP recommended solution and affected software components.
Description
Symptom
An attacker can execute functions in AS Java without authentication and authorization.
Solution
Update your AS Java to a Support Package (SP) or release where the issue is fixed. Refer to the SP Patch Level section for details and available patches.
Reason and prerequisites
The behavior is caused by a problem in HTTP Provider and Web Container services. AS Java executes certain functions by referencing specific URLs. If an attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the user’s rights.
CVSS
Score 7.5 Vector: AV:N/AC:L/AU:N/C:P/I:P/A:P
Affected components
- SAP-JEECOR 7.00 to 7.00
- SAP-JEECOR 6.40 to 6.40
- SAP-JEECOR 7.01 to 7.02
Full note on SAP: SAP Support Launchpad note 1846438
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



