Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

GW Starting programs with log ‘G’, SAP security note 709054

SAP Note 709054

SAP security note 709054, “GW: Starting programs with log ‘G'”, is a note. Below are the symptom, reason and prerequisites, SAP recommended solution and the related references.

Description

Symptom

An attempt to start a program on a remote host using the gateway (connection type ‘G’) fails.

Solution

Use a standalone gateway to start remote programs on systems on which no remote shell is available. You then have the option to check whether the program really can be started. For this, you must maintain the programs to be started in the secinfo file on the Gateway. For details, refer to the documentation.

The gateway documentation is available on the SAP Help Portal under: SAP Netweaver → Release 04 → SAP Library → SAP NetWeaver → Application Platform (SAP Web Application Server) → Connectivity → SAP Communication: Configuration → SAP Gateway.

Reason and prerequisites

Up to Release 4.5x, users had the option of using a gateway (connection type ‘G’) to start programs on remote hosts. For this purpose, a UDP package was sent to the gateway that started the program for RFC/CPIC communication.

This procedure involves risks because no checks can be carried out for the program to be started. For this reason, this start procedure was deactivated.

References

Full note on SAP: SAP Support Launchpad note 709054

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More