SAP security note 2026528, “EAM: RFC capability: Function module F4_FILENAME_SERVER”, is a program error note released on 11.11.2014. Below is the security information published by SAP for this note.
Description
Symptom
The function module F4_FILENAME_SERVER is RFC capable to enable the reading of data from an application server. Calling from external systems is not intended.
Reason and prerequisites
This is due to the system design.
Solution
Implement the attached correction instructions. Afterwards, only an internal RFC call is possible.
References
- 2078596 – Further improvements for RFC security
- 1988903 – Check whether a function modules was called via external RFC
- 1882417 – External check for Remote Function Call
- 1530895 – Transaction IBIP: Potential Directory Traversal
Full note on SAP: SAP Support Launchpad note 2026528
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
