HotNews
SAP security note 604578, "Lockout Bypass Using the RFC_SYSTEM_INFO Function Module", is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The RFC_SYSTEM_INFO function module returns information indicating whether the logon data used was correct, potentially allowing an attacker to bypass account lockout mechanisms.
Solution
To mitigate this vulnerability, implement the following corrections:
- For Version 4.6: update to the 4.6D kernel with patch level 1149.
- For Versions 6.10 and 6.20: the kernel in these versions already includes the necessary corrections.
Refer to the correction instructions for detailed steps on updating the RFC_SYSTEM_INFO function module.
Reason and prerequisites
The RFC_SYSTEM_INFO function module is utilized during the check for free resources for load balancing with asynchronous RFC. Improper handling of logon data responses can lead to vulnerabilities that allow account lockout bypass.
Affected components
- SAP_BASIS: 4.6B to 4.6D (patch level 1149)
- SAP_BASIS: 6.10 to 6.20
Full note on SAP: SAP Support Launchpad note 604578
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




