SAP Security Note
Medium priority
SAP security note 2426076, "Multiple vulnerabilities in SAP ERP Stakeholder Relationship Management", is a program error note released on 11.04.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Denial of Service: The SEM-SRM SMTP inbound class, when assigned inappropriately in customizing of Inbound Exists (SO50), can allow an attacker to prevent legitimate users from accessing a service by crashing or flooding the service.
Impacts of Denial of Service Vulnerability:
- Long response delays and service interruptions, degrading service quality for legitimate users.
- Direct impact on availability.
- Unexpected business partner creation without proper authentication.
Solution
- Do Not Assign: Avoid assigning class CL_USC_CONTACT_SERVICES in SO50 unless you are using the SEM-SRM application.
- Apply Correction: Implement the attached code correction with SNOTE or apply the relevant support package.
- Post-Implementation: After applying the correction, the class will only handle inbound processes belonging to the customized known SRM recipient contacts.
Reason and prerequisites
The issue can only occur when the SRM inbound exit class is used in transaction SO50 and assigned to a recipient email address unrelated to the SRM application.
CVSS
Score 5.3 Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected components
- S4CORE 101
- SEM-BW (versions 320 to 800)
Full note on SAP: SAP Support Launchpad note 2426076
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



