SAP Security Note
HotNews
SAP security note 2260344, “OS command injection vulnerability in SCTC_* Function modules”, is a special development note released on 08.03.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
There is an OS command injection vulnerability in the following function modules when accessed via transaction SE37:
- SCTC_PREPARE_CHECK_CAPACITY
- SCTC_REFRESH_CHECK_ENV
- SCTC_REFRESH_CONFIG_CTC
- SCTC_REFRESH_EXPORT_TAB_COMP
- SCTC_REFRESH_IMPORT_USR_CLNT
- SCTC_REORG_SPOOL
- SCTC_TMS_MAINTAIN_ALOG
These modules contain code that permits the execution of arbitrary program code chosen by the user. An attacker can control the system's behavior without having legitimate credentials.
Solution
Function modules will be re-developed to prevent execution via SE37 and to mitigate OS command injection vulnerabilities.
To check whether your system is affected: log on to your system and start transaction SE24. Enter CL_SCTC_SC_FUNC_POINT as the Object Type and display it. If this object exists, proceed with implementing the correction instructions.
CVSS
Score 9.0 Vector: AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
References
Affected components
- SAP_BASIS: 700 to 702, 710 to 711, 730 to 731, 740 to 750
Full note on SAP: SAP Support Launchpad note 2260344
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
