SAP security note 1826162, "Update 1 to security note 1674132". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This update addresses the need to supplement the correction instructions in security note 1674132, ensuring comprehensive coverage for the specified SAP_BASIS versions.
Solution
Implement the correction instructions attached to this sNote to address the identified vulnerabilities and ensure system security.
Reason and prerequisites
The existing correction instructions in security note 1674132 require supplementation to cover a broader range of SAP_BASIS releases.
CVSS
Score 0
References
- 1674132 – Code injection vulnerability in BC-SRV-COM-FTP
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- BC-SRV-COM-FTP (File Transfer via FTP)
Full note on SAP: SAP Support Launchpad note 1826162
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
