Solution : https://service.sap.com/sap/support/notes/856175 (SAP Service marketplace login required)
Key words : 
update deployed sdas/scas, <server>/services/http directory, <server>/services/http directory    4, <server>/services/servlet_jsp directory, <server>/services/servlet_jsp directory      3, user authentication reason, evade security checks, deployment configuration panel, backup original files, specially handcrafted urls
Related Notes : 
       
| 715371 | |
| 705619 | WEB-INF security vulnerabilities in SAP J2EE Engine 6.20 | 
| 675049 | |
| 656711 | Deploying Java Support Packages with SDM | 
| 646140 | Security Check of Internet Sales | 
| 606733 |