SAP security note 2252312, "Insufficient logging of RFC in SAL". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
RFC Callbacks are logged in Secure Audit Log with misleading severity.
The severity for some RFC Callbacks is maintained incorrectly, leading to potential misunderstandings regarding the actual security impact.
Solution
The severity of the SAL messages "DU J (Callback rejected)" and "DU K (Callback in simulation mode)" has been adjusted to severity critical. Please implement the Support Package mentioned in this SAP Note or follow the correction instructions provided. If you use the correction instructions, the message definition will be updated automatically when starting transaction SM20 or SM19 or running report RSAU_SELECT_EVENTS. No further action is needed to correct the settings.
CVSS
Score 1.7 Vector: AV:L/AC:L/Au:S/C:N/I:P/A:N
References
Referenced by
Affected components
- SAP_BASIS (700 to 750)
Full note on SAP: SAP Support Launchpad note 2252312
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
