SAP Security Note
High priority
SAP security note 1604636, "Update #1 to Security Note 1511462", is a program error note released on October 12, 2011. Below are the symptom and the SAP recommended solution.
Description
Symptom
A vulnerability allows a malicious user to trigger functionality in the SRM Java Tool Box without proper authentication and authorization. This update addresses the vulnerability outlined in Security Note 1511462 for the following Support Package Patch Level: SP10 for SRM JAVATOOLBOX 7.0.
Solution
You can locate SRM Java Tool Box 7.0 in the Support Package and Patch Area of the Service Marketplace.
Reason and prerequisites
Additional information for the Support Package Patch Level has been added to Security Note 1511462. The reference to "SRM 7.01 SP03" has been removed from the solution section of Note 1511462.
References
Full note on SAP: SAP Support Launchpad note 1604636
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
