Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential vulnerability in MFG-MII, SAP security note 1615122

SAP Note 1615122

SAP security note 1615122, "Potential vulnerability in MFG-MII", released on March 13, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSAP Manufacturing Integration and Intelligence (MFG-MII)
StatusReleased for Customer
Released onMarch 13, 2012

Description

Symptom

MFG-MII contains code that changes the program’s behaviour and leads to unforeseeable dependencies or undefined conditions when executed.

Solution

All the malicious code has been removed in MII12.1 SP06 and MII12.2 SP02. Please update to the above-mentioned releases to apply the changes.

Reason and prerequisites

The program code changes the system’s behaviour if executed by a malicious user, who is aware of the loopholes in the code that may lead the system to end up in an undefined condition.

References

Affected components

  • SAP Manufacturing Integration and Intelligence (MFG-MII)
  • XMII 12.1
  • XMII 12.2

Full note on SAP: SAP Support Launchpad note 1615122

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More