SAP Security Note
High priority
SAP security note 1495570, “Security: Execution of any source code”, is a program error note released on February 11, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Due to an error in RKALLOOK, an attacker can execute any user-defined source code. As a result, the attacker can gain control over the system and obtain increased privileges.
Solution
Implement the program corrections described below.
Reason and prerequisites
The program code allows source code that can be determined freely to be added and executed, which enables an attacker to control the system response. Valid logon information is required for this. In addition, the user requires the very high ‘debug-replace’ authorization and must bypass two additional security tests.
References
This note refers to
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Referenced by
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SAP_APPL versions 46C, 470, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1495570
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
