SAP Knowledge Base Article - Preview

3308511 - User session hijacking vulnerability by reusing cookie in AS Java

Symptom

Session theft or hijacking occurs when an attacker has acquired valid user/session cookies and uses them to bypass authentication controls to gain access to the application with privileges in the context of the victim user’s permission level. 


Read more...

Environment

  • SAP NetWeaver Java
  • SAP Enterprise Portal

Product

SAP NetWeaver all versions

Keywords

session fixation, steal, leverage, re-use,  , KBA , BC-JAS-WEB , Web Container, HTTP, JavaMail, Servlets , BC-JAS-SEC , Security, User Management , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.