High priority
SAP security note 830528, "RFC logon: Security problems", is a note released on 19.02.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
- RFC Logon Without Password: You can perform an RFC logon without a password. (This is possible only if you are using an RFC library Version 6.40.)
- Failed Logon Attempts Not Counted: The password logon failed counter does not increase when logon attempts fail after previous RFC system calls. (These are functions of the function module group SRFC.)
Solution
Update to a new kernel:
- Basis Release 3.x: Kernel 3.1I as of patch number 782. See Note 102445.
- Basis Release 4.0x: Kernel 4.0B as of patch number 1070. See Note 102461.
- Basis Release 4.5x: Kernel 4.5B as of patch number 1003. See Note 149682.
- Basis Release 4.6x: Kernel 4.6D as of patch number 2042. See Note 318846.
- Basis Release 6.x: Kernel 6.20 as of patch number 1881 (only for releases lower than 6.40), or Kernel 6.40 as of patch number 69. See Note 502999 or Note 664679.
- Basis Release 7.0 (without Enhancement Packages): Kernel 7.00 as of patch number 2. Or a downward-compatible kernel.
- Basis Release 7.01 (and higher): No corrections required.
Reason and prerequisites
This issue is caused by an error in the kernel and specific versions of the RFC Library:
- librfc_14 (file version 6403.3.58.4600)
- librfc_15 (file version 6403.3.59.4606)
- librfc_16 (file version 6403.3.61.4620)
- librfc_17 (file version 6403.3.62.4629)
- librfc_18 (file version 6403.3.64.4641)
References
- Note 774406 – SM20: "RFC/CPIC login failed, Reason=1, Type=S"
- Note 664679 – Installing 6.40 kernel in SAP WEB AS 6.10/6.20
- Note 318846 – Installing the 4.6D kernel in 4.6A/B/C SAP systems
- Note 19466 – Downloading SAP kernel patches
Full note on SAP: SAP Support Launchpad note 830528
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
