SAP security note 1660428, “Unauthorized modification of stored content in BC-SRV-RM”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability has been identified in BC-SRV-RM that allows an attacker to modify application content and persist these changes without authorization. This can potentially enable the attacker to steal authentication information from other legitimate users, leading to impersonation and unauthorized access to sensitive data. If an administrator’s credentials are compromised, the entire application’s security may be fully breached.
Solution
To mitigate this security issue, please implement SAP Security Note 1660428.
Affected components
- BC-SRV-RM
- SAP_BASIS: 620 to 640
- SAP_BASIS: 700 to 702
- SAP_BASIS: 710 to 730
- SAP_BASIS: 731
Full note on SAP: SAP Support Launchpad note 1660428
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



