Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update #1 for security note 1408081, SAP security note 1525125

SAP Note 1525125
SAP Security Note
Medium priority

SAP security note 1525125, "Update #1 for security note 1408081", is a note released on May 14, 2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology > Gateway/CPIC
PriorityMedium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onMay 14, 2019
LanguageEnglish (Master Language: German)

Description

Symptom

UPDATE 2: May 14, 2019: With update 2 in SAP Note 1408081, this SAP Note is obsolete.

UPDATE 1: November 3, 2010: Correction of some typing errors.

Changes not taken into account in the "Solution" section.

Solution

The corrected minimum configuration is as follows:

  • #VERSION=2
  • P TP=* HOST=local
  • P TP=* HOST=internal CANCEL=internal ACCESS=internal

Reason and prerequisites

Spelling error in the original SAP Note; "internal" is correct, not "interal".

CVSS

Score 4.8 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

References

Affected components

  • KRNL32NUC: 7.20, 7.20EXT
  • KRNL32UC: 7.20, 7.20EXT
  • KRNL64NUC: 7.20, 7.20EXT
  • KRNL64UC: 7.20, 7.2L, 7.20EXT, 8.00
  • KERNEL: 7.20+, 7.2L+, 8.00+

Full note on SAP: SAP Support Launchpad note 1525125

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More