SAP security note 1604055, "Integrated generic callpoint/Treasury & Risk Mgmt.1B", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Hard-coded, generic callpoint for function modules in Treasury and Risk Management.
A malicious user can use a hard-coded, generic callpoint to remotely call up functions that are not intended to be accessed in this way without a suitable authorization check. As a result, the malicious user can execute malicious codes.
Solution
- If you have not already done so, implement the correction instructions from the related Note 1563062 first.
- If necessary, perform the required manual advance tasks for your release first.
- Then implement the attached correction instructions for your release.
- Finally, for BANK/CFM 463_20, EA-FINSERV 110, and EA-FINSERV 200, implement the correction instructions from the related Note 1604933.
Reason and prerequisites
The program code contains a hard-coded, remote-enabled callpoint for function modules that are not intended for remote access.
CVSS
Score 7.5 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:C
References
- Note 1604933 – Integrated generic callpoint/Treasury & Risk Mgmt.1C
- Note 1563062 – Integrated generic callpoint/Treasury & Risk Mgmt.1A
Affected components
- EA-FINSERV, versions 110 to 605
- BANK/CFM, version 463_20
Full note on SAP: SAP Support Launchpad note 1604055
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
