SAP Security Note
Medium priority
SAP security note 2376998, "Missing Authorization Check in EA-DFPS Monitoring Tools", is released on 13.12.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
Some functionality in Solution ‘Defense Forces and Public Security’ (EA-DFPS) for monitoring availability of servers in deployed scenarios lacks authorization and parameter checks.
Impacts of Missing Authorization Check:
- Abuse functionality restricted to a particular user group.
- Read, modify, or delete restricted data.
Solution
- Remove RFC enablement of the function module.
- Add consistency checks on parameters to avoid command injection.
- Apply correction instructions: Apply Correction Instructions.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Full note on SAP: SAP Support Launchpad note 2376998
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




