Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Verb Tampering issues in CMS, SAP security note 1617369

SAP Note 1617369
SAP Security Note
High priority

SAP security note 1617369, “Verb Tampering issues in CMS”, is a program error note released on October 11, 2011. Below are the symptom, SAP recommended solution, references and the affected software components.

ComponentBasis Components > Change and Transport System > Change Management Service (BC-CTS-CMS)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released onOctober 11, 2011
LanguageEnglish

Description

Symptom

There are potential issues with authorization and authentication checks related to different HTTP methods used in the CMS (Change Management Service) of NWDI (NetWeaver Development Infrastructure).

Solution

Apply the patch attached to this note that matches the release and Support Package (SP) level of your AS Java hosting CMS.

Reason and prerequisites

CMS may have Verb Tampering vulnerabilities, which can lead to information disclosure and/or data tampering if accessed with HTTP requests containing unexpected HTTP methods. To mitigate this risk, apply SAP Note 1445998 to disable invokerservlet. Apply both SAP Notes 1617369 and 1445998 to ensure full protection against attacks through servlets of this component. Neither of these notes are strict prerequisites for each other, but both must be applied for complete protection.

References

Affected components

  • DI_CMS 7.00 to 7.31
  • SAP_DEVINF 6.40

Full note on SAP: SAP Support Launchpad note 1617369

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More