Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Integrated generic callpoint/Treasury & Risk Mgmt.1B, SAP security note 1604055

SAP Note 1604055

SAP security note 1604055, "Integrated generic callpoint/Treasury & Risk Mgmt.1B", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Hard-coded, generic callpoint for function modules in Treasury and Risk Management.

A malicious user can use a hard-coded, generic callpoint to remotely call up functions that are not intended to be accessed in this way without a suitable authorization check. As a result, the malicious user can execute malicious codes.

Solution

  • If you have not already done so, implement the correction instructions from the related Note 1563062 first.
  • If necessary, perform the required manual advance tasks for your release first.
  • Then implement the attached correction instructions for your release.
  • Finally, for BANK/CFM 463_20, EA-FINSERV 110, and EA-FINSERV 200, implement the correction instructions from the related Note 1604933.

Reason and prerequisites

The program code contains a hard-coded, remote-enabled callpoint for function modules that are not intended for remote access.

CVSS

Score 7.5 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:C

References

Affected components

  • EA-FINSERV, versions 110 to 605
  • BANK/CFM, version 463_20

Full note on SAP: SAP Support Launchpad note 1604055

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More