SAP security note 1558010, "Hard-coded credentials in FM OIUH_SUBMIT_UNIX_CALL2". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A security vulnerability has been identified in Function Module OIUH_SUBMIT_UNIX_CALL2 within the IS-OIL/PRA systems. This issue allows a backdoor entry, enabling unauthorized users to execute commands remotely via this function. This poses significant risks to data confidentiality and integrity, as directory traversal might be possible.
Solution
The vulnerable function module OIUH_SUBMIT_UNIX_CALL2 has been deleted in the upcoming support pack, effectively eliminating this security risk. Please note that this note cannot be applied via the SNOTE Note Assistant. To apply this note manually, follow the step-by-step procedure provided in the attached Manual_Steps.zip.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- IS-OIL-PRA-REV 46C
- IS-OIL-PRA-REV 472
- IS-OIL-PRA-REV 600
- IS-OIL-PRA-REV 602
- IS-OIL-PRA-REV 603
- IS-PRA 604
- IS-PRA 605
Full note on SAP: SAP Support Launchpad note 1558010
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
