SAP Security Note
Medium priority
SAP security note 2671160, "[CVE-2018-2441] Missing Input Validation in ABAP Change and Transport System (CTS)", is a program error note released on 21.11.2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, the ABAP Change and Transport System (CTS) allows an attacker to transport information which would otherwise be restricted.
Solution
To resolve this vulnerability, perform the following steps:
Update Transport Tools: Install the current versions of the transport tools tp (transport control) and R3trans (transport) in both export and import systems. Refer to the patches provided for your kernel codeline.
Activate Consistency Check: Set the transport profile parameter TLOGOCHECK=TRUE via the Transport Management System (STMS). Call transaction STMS, go to “System Overview” and select the transport domain controller, navigate to the “Transport Tool Configuration” tab, add a new line for the parameter TLOGOCHECK and enter TRUE as the value. To apply globally, mark the “Global” radio button. To apply to selected systems, do not mark the “Global” option and set the parameter individually for each system.
Note: Enabling TLOGOCHECK may cause errors in release spanning transports or if using custom transport object definitions. It is recommended to keep the check disabled in QA systems and monitor transport return codes, and to enable the check in productive systems.
CVSS
Score 5.5 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
References
- SAP Note 19466: Downloading SAP kernel patches
- SAP Note 2713386: Export of deletion transport ends with returncode 0006
Affected components
- KRNL32NUC (versions 7.21, 7.21EXT)
- KRNL32UC (versions 7.21, 7.21EXT)
- KRNL64NUC (versions 7.21 to 7.74)
- KRNL64UC (versions 7.21 to 7.74)
- KERNEL (versions 7.21 to 7.74)
Full note on SAP: SAP Support Launchpad note 2671160
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



