Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

OS command injection vulnerability in SCTC_* Function modules, SAP security note 2260344

SAP Note 2260344
SAP Security Note
HotNews

SAP security note 2260344, “OS command injection vulnerability in SCTC_* Function modules”, is a special development note released on 08.03.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Installation Tools (SAP Note 1669327) > Automated Technical ABAP Configuration > Automation Content
CategorySpecial development
PriorityHotNews
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on08.03.2016
LanguageEnglish

Description

Symptom

There is an OS command injection vulnerability in the following function modules when accessed via transaction SE37:

  • SCTC_PREPARE_CHECK_CAPACITY
  • SCTC_REFRESH_CHECK_ENV
  • SCTC_REFRESH_CONFIG_CTC
  • SCTC_REFRESH_EXPORT_TAB_COMP
  • SCTC_REFRESH_IMPORT_USR_CLNT
  • SCTC_REORG_SPOOL
  • SCTC_TMS_MAINTAIN_ALOG

These modules contain code that permits the execution of arbitrary program code chosen by the user. An attacker can control the system's behavior without having legitimate credentials.

Solution

Function modules will be re-developed to prevent execution via SE37 and to mitigate OS command injection vulnerabilities.

To check whether your system is affected: log on to your system and start transaction SE24. Enter CL_SCTC_SC_FUNC_POINT as the Object Type and display it. If this object exists, proceed with implementing the correction instructions.

CVSS

Score 9.0 Vector: AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H

References

Affected components

  • SAP_BASIS: 700 to 702, 710 to 711, 730 to 731, 740 to 750

Full note on SAP: SAP Support Launchpad note 2260344

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More