High priority
SAP security note 1576215, “Deletion of an obsolete FM EXE_SAPOSCOL”, released on September 11, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of SAPOSCOL to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the relevant Support Package as listed in the note.
CVSS
Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P
Affected components
- SAP_BASIS: Versions 620 to 730
Full note on SAP: SAP Support Launchpad note 1576215
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
