SAP Security Note
High priority
SAP security note 678523, “Security: buffer overun, random numbers, ~session cookie”, is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
This patch solves buffer overuns that may be deliberately triggered by a modification of the ITS URL (if you specify parameters that are too long, for example).
Solution
- ITS 620: this problem is solved with patch level 7.
- For 610/46D, see note 678526.
CVSS
Score 0
References
This note refers to
Full note on SAP: SAP Support Launchpad note 678523
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



