Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure in session management, SAP security note 1478362

SAP Note 1478362High priority

SAP security note 1478362, "Potential information disclosure in session management", released on 14.06.2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Web Container, HTTP, JavaMail, Servlets (BC-JAS-WEB)
PriorityCorrection with high priority
StatusReleased for Customer
Released on14.06.2011

Description

Symptom

Information such as security-related tokens can be exposed through the web container and session management mechanisms. This exposure may allow a malicious user to refine their attacks against user sessions.

Solution

Upgrade to the latest version of Application Server Java to mitigate this vulnerability. For detailed steps and the required Support Package Patch Level, refer to the SAP Note 1478362.

Reason and prerequisites

The vulnerability arises from the ability to access sensitive session management information, including security tokens, via the web container. No specific prerequisites are mentioned beyond the affected components.

References

Full note on SAP: SAP Support Launchpad note 1478362

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More