Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

EAM RFC capability in component CS-SE-FS, SAP security note 2027682

SAP Note 2027682SAP Security NoteMedium priority

SAP security note 2027682, “EAM: RFC capability in component CS-SE-FS”, is a program error note released on 11.11.2014. Below is the security information published by SAP for this note.

ComponentCustomer Service (formerly: PM-SM) > Service Execution > Field Service (CS-SE-FS)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on11.11.2014
LanguageEnglish (Master Language: German)

Description

#### Symptom The function modules PM_CLUSTER_CREATE and IWWO_SERVORDER_CONFIRM are RFC capable. However, calling them from external systems is not intended.

#### Reason and Prerequisites This behavior is due to the system design, which allows these RFC calls internally but not externally.

#### Solution Implement the correction instructions provided in the note. After applying the corrections, only internal RFC calls will be possible.

References

Full note on SAP: SAP Support Launchpad note 2027682

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More