SAP Security Note
Medium priority
SAP security note 1525125, "Update #1 for security note 1408081", is a note released on May 14, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 2: May 14, 2019: With update 2 in SAP Note 1408081, this SAP Note is obsolete.
UPDATE 1: November 3, 2010: Correction of some typing errors.
Changes not taken into account in the "Solution" section.
Solution
The corrected minimum configuration is as follows:
#VERSION=2P TP=* HOST=localP TP=* HOST=internal CANCEL=internal ACCESS=internal
Reason and prerequisites
Spelling error in the original SAP Note; "internal" is correct, not "interal".
CVSS
Score 4.8 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
References
This note refers to
Affected components
- KRNL32NUC: 7.20, 7.20EXT
- KRNL32UC: 7.20, 7.20EXT
- KRNL64NUC: 7.20, 7.20EXT
- KRNL64UC: 7.20, 7.2L, 7.20EXT, 8.00
- KERNEL: 7.20+, 7.2L+, 8.00+
Full note on SAP: SAP Support Launchpad note 1525125
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
