Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update #1 to Security Note 1589525, SAP security note 1624450

SAP Note 1624450

SAP security note 1624450, "Update #1 to Security Note 1589525". Below are the symptom and SAP recommended solution.

Description

Symptom

Patches provided for the verb tampering vulnerability addressed in Security Note 1589525 are re-released after further in-depth investigations. The patches for the following releases have been improved:

  • 6.40
  • 7.0x
  • 7.10, 7.11, 7.20
  • 7.30

Additionally, the manual implementation steps and workarounds have been clarified and enhanced. Note that the manual implementation steps are the preferred solution if you are unable to install the respective SP patch level.

Solution

  • For customers who have already applied the SP patch level for the affected releases: Apply the respective SP patch level again.
  • For customers who followed the manual implementation steps or applied one of the two workarounds: Revisit and perform them again. If you cannot apply the automatic Correction Instruction, we strongly recommend following the manual implementation steps.
  • For customers who have not applied the patch, manual implementation steps, or workarounds: Apply the respective SP patch level or follow the manual implementation steps. If the first two alternatives are not possible, consider one of the two workarounds.

Reason and prerequisites

We have continued to diligently investigate the issue in depth and are now able to re-release improved patches for the releases 6.40, 7.0x, 7.10, 7.11, 7.20, and 7.30. We have also improved descriptions of the workarounds and manual implementation steps.

References

Full note on SAP: SAP Support Launchpad note 1624450

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More