Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

EC-PCA Using FM ZPCA_UPLOAD to load any source code, SAP security note 1479310

Description

Due to an error in the Profit Center Accounting (PCA) retraction, it is possible for an attacker to execute any user-defined source code. This enables the attacker to gain control over the system and obtain secure increased privileges.

Available fix and Supported packages

  • SAP_APPL | 604 | 604
  • SAP_APPL | 605 | 605
  • SAP_APPL 604 | SAPKH60407 |
  • SAP_APPL 605 | SAPKH60502 |

Affected component

    EC-PCA
    Profit Center Accounting

CVSS

Score: 0

Exploit

Exploit is not available.
For detailed information please contact the mail [email protected]

URL

https://launchpad.support.sap.com/#/notes/1479310

TAGS

#Backdoor
#code-upload

More to explorer