Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized display of table contents in RE-FX, SAP security note 1480721

SAP Note 1480721
SAP Security Note
High priority

SAP security note 1480721, "Unauthorized display of table contents in RE-FX", was released on August 10, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentReal Estate Management > Flexible Real Estate Management (RE-FX)
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onAugust 10, 2010
LanguageEnglish (Master Language: German)

Description

Symptom

An attacker can display data for the currency conversion of the component RE-FX, even without the relevant authorization.

Solution

Implement the attached corrections in your system and perform the following manual post-processing steps:

Call transaction SE38. Open the program RFRECA_COMPARE_CLIENTS and specify the following selection texts:

  • NameText
  • P_D_RFC – RFC destination target
  • P_S_RFC – RFC destination source

Reason and prerequisites

The system does not perform any authorization check, allowing unauthorized data access.

CVSS

Score 0

References

Affected components

  • EA-APPL: From 605 to 605

Full note on SAP: SAP Support Launchpad note 1480721

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More