Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

External RFC callback to customer systems in SNOTE, SAP security note 2235513

SAP Note 2235513

SAP security note 2235513, "External RFC Callback Vulnerability in SNOTE". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Unauthorized RFC calls due to a misconfigured SCWN_NOTE_DOWNLOAD RFC connection, potentially allowing exploitation of RFC-enabled function modules on the customer system.

Solution

Apply the corrections provided in this Security Note using the Note Assistant.

Reason and prerequisites

There is a lack of a callback rejection mechanism in the function module SCWN_NOTE_DOWNLOAD. Although Security Note 1686632 provides a callback rejection mechanism, it may not be active on all customer systems, leaving them vulnerable.

Affected components

  • SAP_BASIS 700 to 702
  • SAP_BASIS 710 to 711
  • SAP_BASIS 730, 731, 740, 750

Full note on SAP: SAP Support Launchpad note 2235513

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More