SAP Security Note
Medium priority
SAP security note 1951171, "Potentially controllable RFC function module for postings in EWM", is a program error note released on 01.08.2018. Below is the SAP recommended solution.
Description
Solution
Implement the attached corrections.
Before you implement the source code corrections, make the following changes: use transaction SE11 to create the new structure /SPE/ALLOWED_FM with the following attributes and then activate the structure:
- FUNCTION_NAME (
RS38L_FNAM) - VALID (
XFELD)
This document is causing side effects:
Full note on SAP: SAP Support Launchpad note 1951171
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
