Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Enforcing internal RFC in IS-A, SAP security note 2030674

SAP Note 2030674SAP Security NoteMedium priority

SAP security note 2030674, “Enforcing internal RFC in IS-A”, is a program error note released on 11.11.2014. Below is the security information published by SAP for this note.

ComponentIndustry-Specific Components > Automotive > Supplier Workplace (IS-A-SWP)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on11.11.2014

Description

Symptom

Function modules in IS-A-SWP are remote-enabled and could be called via Remote Function Call (RFC) from remote systems. However, these function modules are intended to be used only internally within the system.

Reason and prerequisites

The remote-enabled flag allows function modules to be accessed both remotely and internally for load distribution across different work processes or application servers. This note ensures that these function modules can only be called internally (same system, same client, and same user context). Remote calls will no longer be processed and will stop the function module processing.

Prerequisite:

  • SAP Note 1988903 must be implemented before applying this correction.

Solution

Implement the support package or the correction instructions provided in this note. SAP note 1988903 is a prerequisite and is also implemented when following the correction instructions.

References

Full note on SAP: SAP Support Launchpad note 2030674

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More