SAP security note 2235513, "External RFC Callback Vulnerability in SNOTE". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Unauthorized RFC calls due to a misconfigured SCWN_NOTE_DOWNLOAD RFC connection, potentially allowing exploitation of RFC-enabled function modules on the customer system.
Solution
Apply the corrections provided in this Security Note using the Note Assistant.
Reason and prerequisites
There is a lack of a callback rejection mechanism in the function module SCWN_NOTE_DOWNLOAD. Although Security Note 1686632 provides a callback rejection mechanism, it may not be active on all customer systems, leaving them vulnerable.
Affected components
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 711
- SAP_BASIS 730, 731, 740, 750
Full note on SAP: SAP Support Launchpad note 2235513
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
