SAP Security Note
High priority
SAP security note 600125, "ITS password logon: incorrect logon counter ineffective", is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
With password-based logons using the ITS (for Workplace, for example), incorrect logon attempts do not cause the user account to lock, nor is the incorrect logon counter incremented. This issue typically occurs with RFC connections when performing a password-based logon using an SNC-secured connection. An entry in table USRACLEXT is required for this, commonly in ITS environments.
Solution
Update to a new kernel version as follows:
- Basis Release 4.6A/4.6B/4.6C/4.6D: kernel 4.6D, as of patch level 1485. Refer to Note 318846.
- Basis Release 6.10/6.20: kernel 6.20, as of patch level 734. Refer to Note 502999.
Reason and prerequisites
This problem is caused by an error in the kernel and only occurs under the conditions described above.
References
- SAP FSCM-Biller Direct: Access to the R/3 via SNC (Note 588717)
- Logon locks for background jobs and internal RFCs (Note 498889)
Full note on SAP: SAP Support Launchpad note 600125
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
