Description
- You are able to perform an RFC logon without a password.
(This is possible only if you are using an RFC library Version 6.40.)
- The password logon failed counter is not increased when logon attempts fail after previous RFC system calls.
(These are functions of the function module group SRFC.)
Available fix and Supported packages
- SAP_APPL | 30C | 30F
- SAP_APPL | 31G | 31I
- SAP_APPL | 40A | 40B
- SAP_APPL | 45A | 45B
- SAP_BASIS | 46A | 46D
- SAP_BASIS | 610 | 640
- SAP_BASIS | 700 | 700
Affected component
- BC-MID-RFC
RFC
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/830528