SAP Security Note
High priority
SAP security note 1648735, "Deletion of experimental FMs from the Package SDIR", is a modification note released on 16.04.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Function Group SDATA, present in the package SDIR, which accesses the database tables violates authorization checks.
Solution
The solution for the issue is to comment out the complete Function Group SDATA, which is present in the package SDIR, as it was just experimental. Neither it is documented nor it is released for reuse.
Note: the flag "Manual activity required after/before installation with SNOTE" is unchecked. By mistake, this flag was checked. Hence, it has been unchecked.
Reason and prerequisites
The Function Group, which has access to database tables, does not have any authorization checks.
CVSS
Score 0
References
This note refers to
Affected components
- SAP_BASIS: From 700 to 702
- SAP_BASIS: From 710 to 730
Full note on SAP: SAP Support Launchpad note 1648735
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
