Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security hole in program ssfrfc on the application server, SAP security note 1438399

Description

Due to a security hole in the program ssfrfc on the application server, malicious users may obtain control of an SAP system.

Available fix and Supported packages

  • SAP_BASIS | 46A | 46D
  • SAP_BASIS | 610 | 640
  • SAP_BASIS | 700 | 702
  • SAP_BASIS | 710 | 711
  • SAP KERNEL 4.6D_EX2 32-BIT | SP2513 | 002513
  • SAP KERNEL 4.6D_EX2 64-BIT | SP2513 | 002513
  • SAP KERNEL 4.6D_EXT 32-BIT | SP2513 | 002513
  • SAP KERNEL 4.6D_EXT 64-BIT | SP2513 | 002513
  • SAP KERNEL 6.40 32-BIT | SP320 | 000320
  • SAP KERNEL 7.00 32-BIT | SP245 | 000245
  • SAP KERNEL 7.00 32-BIT UNICODE | SP245 | 000245
  • SAP KERNEL 7.00 64-BIT | SP245 | 000245
  • SAP KERNEL 7.00 64-BIT UNICODE | SP245 | 000245
  • SAP KERNEL 7.01 32-BIT | SP082 | 000082
  • SAP KERNEL 7.01 32-BIT UNICODE | SP082 | 000082
  • SAP KERNEL 7.01 64-BIT | SP082 | 000082
  • SAP KERNEL 7.01 64-BIT UNICODE | SP082 | 000082
  • SAP KERNEL 7.10 32-BIT | SP189 | 000189
  • SAP KERNEL 7.10 32-BIT UNICODE | SP189 | 000189
  • SAP KERNEL 7.10 64-BIT | SP189 | 000189
  • SAP KERNEL 7.10 64-BIT UNICODE | SP189 | 000189
  • SAP KERNEL 7.11 32-BIT | SP076 | 000076
  • SAP KERNEL 7.11 32-BIT UNICODE | SP076 | 000076
  • SAP KERNEL 7.11 64-BIT | SP076 | 000076
  • SAP KERNEL 7.11 64-BIT UNICODE | SP076 | 000076

Affected component

    BC-SEC-SSF
    Secure Store and Forward

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1438399

TAGS

#

Explore More

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.