HotNews
SAP security note 1604933, “Integrated generic callpoint/Treasury & Risk Mgmt.1C”, is a program error note released on September 13, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Malicious users can exploit hard-coded callpoints to access unauthorized functions, potentially compromising system integrity.
Solution
- Prerequisite: implement the correction instructions from the related notes 1563062 and 1604055 first.
- Implementation: apply the attached correction instructions specific to your release. Ensure that all prerequisites are met before proceeding with the implementation to avoid potential issues.
CVSS
Score 7.5 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:C
References
- 1604055 – Integrated generic callpoint/Treasury & Risk Mgmt.1B
- 1563062 – Integrated generic callpoint/Treasury & Risk Mgmt.1A
Affected components
- EA-FINSERV (110)
- EA-FINSERV (200)
- BANK/CFM (463_20)
Full note on SAP: SAP Support Launchpad note 1604933
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
