Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Execution of any source code, SAP security note 1495570

SAP Note 1495570
SAP Security Note
High priority

SAP security note 1495570, “Security: Execution of any source code”, is a program error note released on February 11, 2011. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
StatusReleased for Customer
Released onFebruary 11, 2011

Description

Symptom

Due to an error in RKALLOOK, an attacker can execute any user-defined source code. As a result, the attacker can gain control over the system and obtain increased privileges.

Solution

Implement the program corrections described below.

Reason and prerequisites

The program code allows source code that can be determined freely to be added and executed, which enables an attacker to control the system response. Valid logon information is required for this. In addition, the user requires the very high ‘debug-replace’ authorization and must bypass two additional security tests.

References

This note refers to

  • SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)

Referenced by

  • SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)

Affected components

  • SAP_APPL versions 46C, 470, 500, 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1495570

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More