Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security note Forbidden program execution possible, SAP security note 1298160

SAP Note 1298160
SAP Security Note
HotNews

SAP security note 1298160, “Security note: Forbidden program execution possible”, is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Change and Transport System > Transport Management System
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

You are able to execute undesired source code in the system using a special call of an RFC module.

Solution

Import the Support Package or implement the correction instructions. The corrections do not have an influence on the normal function of the application. We strongly recommend that you implement this note to eliminate this security flaw. We do not assume any responsibility if you omit to implement this note and any damage occurs as a result.

After implementing the solution, attempts to exploit this vulnerability will be logged in the system log with the message: ‘IM 0 Attack from:’ and additional information.

Reason and prerequisites

This problem is caused by a program error.

References

Affected components

  • SAP_BASIS from version 700 to 702
  • SAP_BASIS from version 710 to 720

Full note on SAP: SAP Support Launchpad note 1298160

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More