SAP security note 1478362, "Potential information disclosure in session management", released on 14.06.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Information such as security-related tokens can be exposed through the web container and session management mechanisms. This exposure may allow a malicious user to refine their attacks against user sessions.
Solution
Upgrade to the latest version of Application Server Java to mitigate this vulnerability. For detailed steps and the required Support Package Patch Level, refer to the SAP Note 1478362.
Reason and prerequisites
The vulnerability arises from the ability to access sensitive session management information, including security tokens, via the web container. No specific prerequisites are mentioned beyond the affected components.
References
Full note on SAP: SAP Support Launchpad note 1478362
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



