SAP Security Note
SAP security note 1560360, "Security vulnerability in remote FM OIUH_SUBMIT_UNIX_CALL", released on May 9, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A critical security vulnerability has been identified in the SAP component OIUH_SUBMIT_UNIX_CALL, which allows remote users to execute arbitrary OS commands on the SAP server via RFC. This vulnerability poses significant risks to data confidentiality and integrity due to the potential for directory traversal attacks.
The vulnerable function module OIUH_SUBMIT_UNIX_CALL is no longer in use within PRA and has been deleted in the upcoming support pack. However, until the patch is applied, systems using this function are at risk of unauthorized command execution and directory traversal, potentially leading to severe data breaches.
Solution
To mitigate this vulnerability, manual deletion of the obsolete RFC function OIUH_SUBMIT_UNIX_CALL is required. Follow the steps below:
- Access transaction SE37 in your SAP system.
- Enter the function module name OIUH_SUBMIT_UNIX_CALL. Click the Delete button (or press Shift+F2) on the application toolbar. Confirm deletion by clicking Yes in the popup dialog Delete Function Module.
- Save the deletion in a transport request to apply it to other systems within your landscape.
The deletion will be available in the next support pack. For urgent implementation, refer to SAP Note 47531.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- IS-OIL 46C
- IS-OIL 472
- IS-OIL 600
- IS-OIL 602
- IS-OIL 603
- IS-PRA 604
- IS-PRA 605
Full note on SAP: SAP Support Launchpad note 1560360
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
