SAP Security Note
Medium priority
SAP security note 1421523, "No examples shipped with SAP J2EE Engine 6.40 and 7.0x", is a program error note released on 11.02.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
- After applying the respective service packs listed below, the examples originally shipped with the J2EE engine are no longer available.
- Possible path traversal with shipped examples.
Solution
Undeploy the examples that come with the Engine and use the examples in the NetWeaver Developer Studio.
It is strongly recommended to undeploy (if deployed) the following applications:
- Calculator
- Servlet Filter
- Hello
- Increment
- JavaMailExamples
- MDB
- Shop
Reason and prerequisites
The example applications which were originally shipped with the Engine provided demonstrations for basic J2EE functionality.
The scenarios covered by the example applications have been revised and enriched by more versatile samples that are closer to real usage and do not contain the security issues (related to possible path traversal) present in the previously shipped examples.
These new examples are shipped with the NetWeaver Developer Studio and can be built and deployed from it.
The example applications have been deleted from the Engine packages in the following versions:
- SAP J2EE Engine 6.40 – SP 20
- SAP J2EE Engine 7.00 – SP 22
- SAP J2EE Engine 7.01 – SP 07
- SAP J2EE Engine 7.02 – SP 03
CVSS
Score 0
References
This note refers to
Affected components
- SAP_JTECHS: 6.40
- SAP_JTECHS: 7.00 to 7.02
Full note on SAP: SAP Support Launchpad note 1421523
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



