SAP Security Note
High priority
SAP security note 606733, “SAP J2EE – composite SAP note on security of Basis 6.20”, is a note released on 30.11.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Security-relevant settings/corrections for the J2EE server.
Solution
Composite SAP Note on the topic of security in J2EE Basis 6.20.
The following notes are currently available on this topic:
- 531495 How to disable directory browsing in SAP J2EE Engine
- 602371 All users for Telnet authorized for R/3
- 603142 J2EE users after installation without password
- 604285 Security vulnerability by unprotected HTTP PUT method
- 622447 SAP Biller Direct 2.0 installation note (Java component)
- 646140 Security check of Internet Sales
- 705619 WEB-INF Security vulnerabilities in SAP J2EE Engine 6.20
Reason and prerequisites
This concerns J2EE 6.20.
References
This note refers to
- 856175 Access to protected resources may be granted
- 740499 EP 6.0 SP2: Portal Platform Security Guide
- 705619 WEB-INF security vulnerabilities in SAP J2EE Engine 6.20
- 646140 Security Check of Internet Sales
- 645876 Configuring SNC (J2EE Engine <–> ABAP using JCo)
- 622447 Installation note for SAP Biller Direct 2.0 (Java component)
- 604285 J2EE: Security vulnerability by unprotected HTTP PUT method
- 531495 How to disable/enable directory browsing in SAP J2EE Engine
Referenced by
- 531495 How to disable/enable directory browsing in SAP J2EE Engine
- 856175 Access to protected resources may be granted
- 645876 Configuring SNC (J2EE Engine <–> ABAP using JCo)
- 740499 EP 6.0 SP2: Portal Platform Security Guide
- 705619 WEB-INF security vulnerabilities in SAP J2EE Engine 6.20
- 622447 Installation note for SAP Biller Direct 2.0 (Java component)
Affected components
- SAP-JEE: Versions 6.20 to 6.20
Full note on SAP: SAP Support Launchpad note 606733
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




