SAP Security Note
HotNews
SAP security note 2235514, "Standard RFC destination for note download can be overridden", is a program error note released on 13.11.2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
There is a chance to override the standard RFC destination used for downloading the note.
Solution
Apply the corrections attached to the note using Note Assistant.
Reason and prerequisites
The program SCWN_NOTE_DOWNLOAD reads the RFC destination from the CWBRFCUSR table and, if it exists, uses this destination for downloading the note instead of the standard RFC destination.
Affected components
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 711
- SAP_BASIS 730
- SAP_BASIS 731
- SAP_BASIS 740
- SAP_BASIS 750
Full note on SAP: SAP Support Launchpad note 2235514
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
