Skip links
🔥🔥🔥 Join us for our upcoming training session at Black Hat MEA: "Securing SAP Systems: Expert Insights and Penetration Testing Techniques" 🛡️🔍

EC-PCA Using FM ZPCA_UPLOAD to load any source code, SAP security note 1479310

Description

Due to an error in the Profit Center Accounting (PCA) retraction, it is possible for an attacker to execute any user-defined source code. This enables the attacker to gain control over the system and obtain secure increased privileges.

Available fix and Supported packages

  • SAP_APPL | 604 | 604
  • SAP_APPL | 605 | 605
  • SAP_APPL 604 | SAPKH60407 |
  • SAP_APPL 605 | SAPKH60502 |

Affected component

    EC-PCA
    Profit Center Accounting

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1479310

TAGS

#Backdoor
#code-upload

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer