Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use web application sessions in LOD-ESO-AS, SAP security note 1626450

SAP Note 1626450
SAP Security Note
Medium priority

SAP security note 1626450, "Unauthorized use web application sessions in LOD-ESO-AS", is a program error note released on 12.06.2012. Below are the symptom and SAP recommended solution.

ComponentOnDemand > Sourcing OnDemand > Accounts & Security
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on12.06.2012
LanguageEnglish

Description

Symptom

An attacker can access active sessions in LOD-ESO-AS without authentication and authorization. This access allows the attacker to use application functionality to which access should be restricted. Furthermore, discovered information could be used to allow the attacker to specialize their attack against LOD-ESO-AS.

Solution

Code changes were provided to address the issue. Customers should upgrade SAP SOURCING/CLM to Version 5.0 patch J, or Version 5.1 Patch 10 or to any Version 7.0 release which will include the fix for this vulnerability.

Reason and prerequisites

LOD-ESO-AS maintains active sessions by referencing them via session IDs. When an attacker tricks the server into accepting an attacker-generated ID that refers to an active session, the attacker can perform all the actions the authenticated user can perform.

Full note on SAP: SAP Support Launchpad note 1626450

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More