High priority
SAP security note 1839511, "Update 2 to security note 1651004," is a note released on 28.03.2013. Below are the symptom and the SAP recommended solution.
Description
Symptom
Security note 1651004 has been rereleased due to missing validity entries. Newly added releases that are affected are listed below:
- SAP J2EE ENGINE 640 SP26, SP27, SP28, SP29
- SAP J2EE ENGINE 700 SP23, SP24, SP25, SP26
- SAP J2EE ENGINE 701 SP07, SP08, SP09, SP10
- SAP J2EE ENGINE 702 SP05, SP06, SP07, SP08, SP09, SP10
- PORTAL PLATFORM 6.0_640 SP26, SP27, SP28, SP29
- SAP J2EE ENGINE CORE 700 SP23, SP24, SP25, SP26
- SAP J2EE ENGINE CORE 701 SP07, SP08, SP09, SP10
- SAP J2EE ENGINE CORE 702 SP05, SP06, SP07, SP08, SP09, SP10
- SAP JAVA TECH SERVICES 700 SP23, SP24, SP25, SP26
- SAP JAVA TECH SERVICES 701 SP07, SP08, SP09, SP10
- SAP JAVA TECH SERVICES 702 SP05, SP06, SP07, SP08, SP09, SP10
- PORTAL FRAMEWORK 700 SP23, SP24, SP25, SP26
- PORTAL FRAMEWORK 701 SP07, SP08, SP09, SP10
- PORTAL FRAMEWORK 702 SP05, SP06, SP07, SP08, SP09, SP10
Solution
There are no special steps to be performed. Note 1651004 has already been updated with the correct entries, so when applying it, you don’t need to do any additional work.
Reason and prerequisites
The validity of security note 1651004 has been extended with further affected releases.
References
Full note on SAP: SAP Support Launchpad note 1839511
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
