Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in AS Java, SAP security note 1846438

SAP Note 1846438SAP Security NoteMedium priority

SAP security note 1846438, "Unauthorized use of application functions in AS Java", is a program error note released on 11.02.2014. Below are the symptom, SAP recommended solution and affected software components.

ComponentBasis Components > NetWeaver Application Server Java > Web Container, HTTP, JavaMail, Servlets
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on11.02.2014
LanguageEnglish

Description

Symptom

An attacker can execute functions in AS Java without authentication and authorization.

Solution

Update your AS Java to a Support Package (SP) or release where the issue is fixed. Refer to the SP Patch Level section for details and available patches.

Reason and prerequisites

The behavior is caused by a problem in HTTP Provider and Web Container services. AS Java executes certain functions by referencing specific URLs. If an attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the user’s rights.

CVSS

Score 7.5 Vector: AV:N/AC:L/AU:N/C:P/I:P/A:P

Affected components

  • SAP-JEECOR 7.00 to 7.00
  • SAP-JEECOR 6.40 to 6.40
  • SAP-JEECOR 7.01 to 7.02

Full note on SAP: SAP Support Launchpad note 1846438

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More