Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Hard-coded credentials in FM OIUH_SUBMIT_UNIX_CALL2, SAP security note 1558010

SAP Note 1558010

SAP security note 1558010, "Hard-coded credentials in FM OIUH_SUBMIT_UNIX_CALL2". Below are the symptom, SAP recommended solution and the affected software components.

ComponentIS-OIL-PRA-REV

Description

Symptom

A security vulnerability has been identified in Function Module OIUH_SUBMIT_UNIX_CALL2 within the IS-OIL/PRA systems. This issue allows a backdoor entry, enabling unauthorized users to execute commands remotely via this function. This poses significant risks to data confidentiality and integrity, as directory traversal might be possible.

Solution

The vulnerable function module OIUH_SUBMIT_UNIX_CALL2 has been deleted in the upcoming support pack, effectively eliminating this security risk. Please note that this note cannot be applied via the SNOTE Note Assistant. To apply this note manually, follow the step-by-step procedure provided in the attached Manual_Steps.zip.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

Affected components

  • IS-OIL-PRA-REV 46C
  • IS-OIL-PRA-REV 472
  • IS-OIL-PRA-REV 600
  • IS-OIL-PRA-REV 602
  • IS-OIL-PRA-REV 603
  • IS-PRA 604
  • IS-PRA 605

Full note on SAP: SAP Support Launchpad note 1558010

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More