SAP security note 1995783, “Authority check for remote enabled Function Module SELECT_COUNT”, is a program error note released on 11.11.2014. Below is the security information published by SAP for this note.
Description
Symptom
An attacker can discover information relating to Function Module SELECT_COUNT that is used in SAP_AP. This information could be used to allow the attacker to specialize their attacks against Function Module SELECT_COUNT and SAP_AP.
Reason and prerequisites
Information can be discovered using Function Module SELECT_COUNT. This information may be used by an attacker to further target SAP_AP.
Solution
Please apply the attached correction instruction.
## Actions
- Download for SNOTE
- PDF Version
- Share by Email
- Open in New Window
## References
## Validity
- Software Component: SAP_AP
- From: 700
- To: 700
## Support Package
## Correction Instructions
*Credits: Red Rays for support and provided information.*
Full note on SAP: SAP Support Launchpad note 1995783
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
