SAP Security Note
Medium priority
SAP security note 1334964, “External commands and SNC”, is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution and reason and prerequisites.
Description
Symptom
You want to ensure that no intruder calls external commands in your system.
Solution
You can now authenticate the caller of an external command using SNC (Secure Network Communication). (Technical information: Since an external command is always called via the RFC server program sapxpg, the caller is authenticated by sapxpg.)
You must activate the new function because it is not the default setting. To use the new function, you must make settings on the calling side (SAP system) and on the target side (sapxpg). The attached document describes this topic in detail.
Reason and prerequisites
An authentication of the caller is missing in the previous security measure that is described in Note 866732.
Full note on SAP: SAP Support Launchpad note 1334964
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
