SAP Security Note
HotNews
SAP security note 604816, "Lockout bypass through function module RFC_SYSTEM_INFO", is a note released on January 11, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The function module RFC_SYSTEM_INFO returns information as to whether the used logon data was correct.
Solution
The correction must be made in function module RFC_SYSTEM_INFO as described in the correction instructions.
Note: If the correction is implemented, a restricted load distribution can occur depending on the scenarios used.
Reason and prerequisites
The function module RFC_SYSTEM_INFO is used in the check of the free resources for load distribution with the asynchronous RFC.
Affected components
- SAP_APPL from 31I to 31I
- SAP_APPL from 40A to 40B
- SAP_APPL from 45A to 45B
Full note on SAP: SAP Support Launchpad note 604816
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



