SAP security note 1615122, "Potential vulnerability in MFG-MII", released on March 13, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
MFG-MII contains code that changes the program’s behaviour and leads to unforeseeable dependencies or undefined conditions when executed.
Solution
All the malicious code has been removed in MII12.1 SP06 and MII12.2 SP02. Please update to the above-mentioned releases to apply the changes.
Reason and prerequisites
The program code changes the system’s behaviour if executed by a malicious user, who is aware of the loopholes in the code that may lead the system to end up in an undefined condition.
References
Affected components
- SAP Manufacturing Integration and Intelligence (MFG-MII)
- XMII 12.1
- XMII 12.2
Full note on SAP: SAP Support Launchpad note 1615122
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
