SAP Security Note
Medium priority
SAP security note 1626450, "Unauthorized use web application sessions in LOD-ESO-AS", is a program error note released on 12.06.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can access active sessions in LOD-ESO-AS without authentication and authorization. This access allows the attacker to use application functionality to which access should be restricted. Furthermore, discovered information could be used to allow the attacker to specialize their attack against LOD-ESO-AS.
Solution
Code changes were provided to address the issue. Customers should upgrade SAP SOURCING/CLM to Version 5.0 patch J, or Version 5.1 Patch 10 or to any Version 7.0 release which will include the fix for this vulnerability.
Reason and prerequisites
LOD-ESO-AS maintains active sessions by referencing them via session IDs. When an attacker tricks the server into accepting an attacker-generated ID that refers to an active session, the attacker can perform all the actions the authenticated user can perform.
Full note on SAP: SAP Support Launchpad note 1626450
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
