Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

EC-PCA Using FM ZPCA_UPLOAD to load any source code, SAP security note 1479310

Description

Due to an error in the Profit Center Accounting (PCA) retraction, it is possible for an attacker to execute any user-defined source code. This enables the attacker to gain control over the system and obtain secure increased privileges.

Available fix and Supported packages

  • SAP_APPL | 604 | 604
  • SAP_APPL | 605 | 605
  • SAP_APPL 604 | SAPKH60407 |
  • SAP_APPL 605 | SAPKH60502 |

Affected component

    EC-PCA
    Profit Center Accounting

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1479310

TAGS

#Backdoor
#code-upload

Explore More

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.