SAP Security Note
High priority
SAP security note 1480721, "Unauthorized display of table contents in RE-FX", was released on August 10, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can display data for the currency conversion of the component RE-FX, even without the relevant authorization.
Solution
Implement the attached corrections in your system and perform the following manual post-processing steps:
Call transaction SE38. Open the program RFRECA_COMPARE_CLIENTS and specify the following selection texts:
- NameText
- P_D_RFC – RFC destination target
- P_S_RFC – RFC destination source
Reason and prerequisites
The system does not perform any authorization check, allowing unauthorized data access.
CVSS
Score 0
References
This note refers to
Affected components
- EA-APPL: From 605 to 605
Full note on SAP: SAP Support Launchpad note 1480721
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
