SAP Security Note
HotNews
SAP security note 1511107, “Executing freely determined code using transaction SE37”, was released on 09.11.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Using a function module of the Controlling (CO) component, an attacker can execute any user-defined source code. This vulnerability allows the attacker to gain control over the system and obtain elevated privileges, potentially leading to unauthorized access, data manipulation, and system disruption.
Solution
Implement the attached correction instructions.
References
- 1525695: Update #1 for Note 587410: Missing Authorization Check SE37
- 888889: Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- Controlling > Overhead Cost Controlling (CO-OM)
Full note on SAP: SAP Support Launchpad note 1511107
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
