SAP Security Note
HotNews
SAP security note 1563062, "Integrated generic callpoint/Treasury & Risk Mgmt.1A", is released on September 13, 2011. Below are the symptom and the affected software components.
Description
Symptom
A hard-coded, generic callpoint for function modules in Treasury and Risk Management allows a malicious user to remotely execute functions without proper authorization checks. This vulnerability can lead to the execution of malicious code, posing significant security risks to affected systems.
Exploitation of this vulnerability enables unauthorized remote access to sensitive function modules, potentially allowing attackers to execute arbitrary code and compromise the integrity and availability of the SAP system.
CVSS
Score 7.5 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:C
References
- 1604055 – Integrated generic callpoint/Treasury & Risk Mgmt.1B
- 1604933 – Integrated generic callpoint/Treasury & Risk Mgmt.1C
Affected components
- EA-FINSERV 110, 200, 500, 600, 603, 604, 605
- BANK/CFM 463_20
Full note on SAP: SAP Support Launchpad note 1563062
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
