Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update 1 to Security Note 1584573, SAP security note 1977547

SAP Note 1977547SAP Security NoteHigh priority

SAP security note 1977547, "Update 1 to Security Note 1584573", is a program error note released on 06.02.2018. Below are the symptom, SAP recommended solution, CVSS score and the affected software components.

ComponentBasis Components > Upgrade – general > Upgrade Tools (SUM) > Upgrade tools for ABAP
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on06.02.2018
LanguageEnglish

Description

Symptom

This SAP Note supplements the correction instructions in Security Note 1584573. It addresses scenarios where the original instructions may not be fully applicable due to the system's installation history or updates applied using Software Update Manager (SUM).

Exception: this security note is only relevant for newly installed systems or systems that have never been changed using Software Update Manager 1.0 or 2.0 since the note was created. If you have used Software Update Manager since 2014, set this note to "not relevant."

Solution

The update addresses an object that is part of the update tools delivered via SUM 1.0. The correction depends on the release and support package level of SAP_BASIS, as well as the system's update history.

Possible Scenarios:

  • Function Module SUGM_UPG_TYPE_PLUS_DEL_XML does not exist: ignore both this note and Security Note 1584573.
  • Function Module is part of Function Group SUNP: ignore both notes, as Function Group SUNP delivers a secure version of the object.
  • Note 1584573 has been successfully applied: ignore this update note.
  • Note 1584573 not applied or failed: apply this update note. Valid for SAP_BASIS releases 700 to 702 and 710 to 730.

CVSS

Score 0

References

Affected components

  • SAP_BASIS: from 700 to 702
  • SAP_BASIS: from 710 to 730
  • SAP_BASIS: 731

Full note on SAP: SAP Support Launchpad note 1977547

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More