Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

EC-PCA Using FM ZPCA_UPLOAD to load any source code, SAP security note 1479310

Description

Due to an error in the Profit Center Accounting (PCA) retraction, it is possible for an attacker to execute any user-defined source code. This enables the attacker to gain control over the system and obtain secure increased privileges.

Available fix and Supported packages

  • SAP_APPL | 604 | 604
  • SAP_APPL | 605 | 605
  • SAP_APPL 604 | SAPKH60407 |
  • SAP_APPL 605 | SAPKH60502 |

Affected component

    EC-PCA
    Profit Center Accounting

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1479310

TAGS

#Backdoor
#code-upload

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,