SAP security note 2030674, “Enforcing internal RFC in IS-A”, is a program error note released on 11.11.2014. Below is the security information published by SAP for this note.
Description
Symptom
Function modules in IS-A-SWP are remote-enabled and could be called via Remote Function Call (RFC) from remote systems. However, these function modules are intended to be used only internally within the system.
Reason and prerequisites
The remote-enabled flag allows function modules to be accessed both remotely and internally for load distribution across different work processes or application servers. This note ensures that these function modules can only be called internally (same system, same client, and same user context). Remote calls will no longer be processed and will stop the function module processing.
Prerequisite:
- SAP Note 1988903 must be implemented before applying this correction.
Solution
Implement the support package or the correction instructions provided in this note. SAP note 1988903 is a prerequisite and is also implemented when following the correction instructions.
References
- 2078596 – Further improvements for RFC security
- 1624291 – Syntax error when implementing a security note
Full note on SAP: SAP Support Launchpad note 2030674
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
