Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Deletion of experimental FMs from the Package SDIR, SAP security note 1648735

SAP Note 1648735
SAP Security Note
High priority

SAP security note 1648735, "Deletion of experimental FMs from the Package SDIR", is a modification note released on 16.04.2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > NetWeaver Process Integration (PI) > Integration Builder – Design
CategoryModification
PriorityCorrection with high priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on16.04.2012
LanguageEnglish

Description

Symptom

The Function Group SDATA, present in the package SDIR, which accesses the database tables violates authorization checks.

Solution

The solution for the issue is to comment out the complete Function Group SDATA, which is present in the package SDIR, as it was just experimental. Neither it is documented nor it is released for reuse.

Note: the flag "Manual activity required after/before installation with SNOTE" is unchecked. By mistake, this flag was checked. Hence, it has been unchecked.

Reason and prerequisites

The Function Group, which has access to database tables, does not have any authorization checks.

CVSS

Score 0

References

Affected components

  • SAP_BASIS: From 700 to 702
  • SAP_BASIS: From 710 to 730

Full note on SAP: SAP Support Launchpad note 1648735

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More