SAP security note 1479310, "EC-PCA: Using FM ZPCA_UPLOAD to load any source code", was released on September 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
Due to an error in the Profit Center Accounting (PCA) retraction, it is possible for an attacker to execute any user-defined source code. This enables the attacker to gain control over the system and obtain secure increased privileges.
Solution
Implement the attached corrections.
Reason and prerequisites
There is a program error.
Full note on SAP: SAP Support Launchpad note 1479310
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



