SAP Security Note
Medium priority
SAP security note 1496038, "Unsecure standard configuration", is a program error note released on 13.09.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can access the current data about a Web Dynpro ABAP session of a different user without authorization by exploiting the unsecure configuration setting.
Solution
Implement the correction instructions or import the relevant Support Package. This note temporarily deactivates the relevant function without adversely affecting Web Dynpro ABAP applications in production. The function will be available again in a later Support Package. Alternatively, an additional note will enable you to reactivate the function.
Reason and prerequisites
By exploiting the unsecure standard configuration, the malicious user gains access to the current data of a legitimate user’s session. The attack can occur by presenting a link to the victim.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1496038
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
