Search This Blog

Monday, June 13, 2011

SAP Note 1298160 - Security note: Forbidden program execution possible

Symptom
You are able to execute undesired source code in the system using a special call of an RFC module.


Other terms
Security


Reason and Prerequisites
This problem is caused by a program error.


Solution
Import the Support Package or implement the correction instructions.
The corrections do not have an influence on the normal function of the application.
We strongly recommend that you implement this note to eliminate this security flaw.
We do not assume any responsibility if you omit to implement this note and any damage occurs as a result.

After that, you can no longer use this gap. Instead, each attempt will be logged in the system log with the message: 'IM 0 Attack from:' and additional information.




Affected Releases
Software
Component
Release
From
Release
To
Release
And
subsequent
SAP_BASIS
70
700
702
 
SAP_BASIS
71
710
720
 

Correction delivered in Support Package
Support
Packages
Release
Package
Name
SAP_BASIS
700
SAP_BASIS
701
SAP_BASIS
710
SAP_BASIS
711

Corrections Instructions
Correction
Instruction
Valid
from
Valid
to
Software
Component
Last
Modifcation
710
711
SAP_BASIS
24.01.2009  20:36:18
700
701
SAP_BASIS
24.01.2009  20:37:17


Direct Link : https://service.sap.com/sap/support/notes/1298160

No comments:

Post a Comment