Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unsecure standard configuration, SAP security note 1496038

SAP Note 1496038
SAP Security Note
Medium priority

SAP security note 1496038, "Unsecure standard configuration", is a program error note released on 13.09.2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Web Dynpro > Web Dynpro ABAP
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on13.09.2011
LanguageEnglish

Description

Symptom

A malicious user can access the current data about a Web Dynpro ABAP session of a different user without authorization by exploiting the unsecure configuration setting.

Solution

Implement the correction instructions or import the relevant Support Package. This note temporarily deactivates the relevant function without adversely affecting Web Dynpro ABAP applications in production. The function will be available again in a later Support Package. Alternatively, an additional note will enable you to reactivate the function.

Reason and prerequisites

By exploiting the unsecure standard configuration, the malicious user gains access to the current data of a legitimate user’s session. The attack can occur by presenting a link to the victim.

References

Full note on SAP: SAP Support Launchpad note 1496038

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More