Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential bypass of unified connectivity runtime checks possible in BC-MID-RFC, SAP security note 2245130

SAP Note 2245130
SAP Security Note

SAP security note 2245130, “Potential bypass of unified connectivity runtime checks possible in BC-MID-RFC”, is a note released on July 15, 2022. Below are the symptom, SAP recommended solution and the affected software components.

TypeSAP Security Note
Released onJuly 15, 2022

Description

Symptom

A vulnerability was identified in the Unified Connectivity (UCON) component of BC-MID-RFC where a bypass of runtime checks is possible if the first user logon attempt fails. This bypass can potentially allow unauthorized access by circumventing essential security checks.

Solution

To mitigate this vulnerability, apply the following patches and support packages.

WarningDo not de-implement the ABAP corrections of this SAP Note as it may cause system errors.
WarningImplementing ABAP corrections without the corresponding kernel patches will render them ineffective.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

Affected components

  • KRNL64NUC: Version 7.42
  • KRNL64UC: Version 7.42
  • SAP_BASIS: Versions 740, 750
  • KERNEL: Versions 7.42, 7.45

Full note on SAP: SAP Support Launchpad note 2245130

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More