Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Multiple entry points to client code, SAP security note 1536124

SAP Note 1536124
SAP Security Note
Medium priority

SAP security note 1536124, "Multiple entry points to client code", released on 08.03.2011. Below are the symptom and SAP recommended solution.

ComponentBC-MOB-LAP – Basis Components > SAP NetWeaver Mobile Infrastructure > Laptop Client for Data Orchestration Engine (DOE)
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on08.03.2011

Description

Symptom

Multiple entry points to client code in BC-MOB-LAP, BC-MOB-PDA.

Solution

The correction is implemented for this issue. To obtain the fix, please upgrade the client to at least the patch level specified in the "SP Patch Level" section of this note, relevant to your release and Support Package (SP).

Reason and prerequisites

NetWeaver Mobile client code has multiple entry points. A malicious user can run the functions which have these entry points without starting the client in the normal manner. The user can therefore execute pieces of client code as if they were standalone functions, resulting in unexpected and potentially unpleasant behavior.

References

Full note on SAP: SAP Support Launchpad note 1536124

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More