SAP Security Note
High priority
SAP security note 617549, "RFC Patch Collection 02 2003", was released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This is a program error in the remote function call area.
Solution
The following errors and enhancements were corrected with this Patch Collection:
- Release 4.6D: (617703) GUID: fixed generation of doubled GUID on AIX; (617670) fixed leak while sending many tables with RFC.
- Release 6.20: (617703) GUID: fixed generation of doubled GUID on AIX; (617670) fixed leak while sending many tables with TRFC; corrected error messages issued if a Unicode conversion error occurs; the RFC library performs a logon before SAPGUI is started using 'SYSTEM_RFC_VERSION_3_INIT' calls, after which the complete authorization check is performed.
The errors are corrected with the following Support Package levels: 46D: ABAP kernel patch level 1503; 620: ABAP kernel patch level 792.
Reason and prerequisites
Various errors in the kernel and RFC library.
Affected components
- SAP_BASIS: 46C to 46D+
- SAP_BASIS: 610 to 640+
Full note on SAP: SAP Support Launchpad note 617549
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



