SAP Security Note
Medium priority
SAP security note 1649912, “Update 1 for Security Note 1298433”, is a program error note released on 14.02.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
The solution for the vulnerability described in Note 1298433 (Bypassing security in reginfo & secinfo) is provided for the following additional Support Package patch level.
Kernel release 701, patch level 171.
Solution
Apply the kernel corrections that are specified on the “SP Patch Level” tab.
Reason and prerequisites
Solutions for further Support Package patch levels must be provided for security note 1298433.
References
- 888889: Automatic checks for security notes using RSECNOTE (outdated)
- 1298433: Bypassing security in reginfo & secinfo
Full note on SAP: SAP Support Launchpad note 1649912
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
