SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.
An attacker with administrator privileges exploits a functional module exposed through the RFC (Remote Function Call) interface. The vulnerability lies in insufficient input data validation (CWE-94: Improper Control of Code Generation), which allows injection of arbitrary ABAP code or operating system commands. The mechanism bypasses required authorization controls, acting in practice as a backdoor. As a result, the attacker gains full control over the system, compromising its confidentiality, integrity and availability.
An attacker can achieve full compromise of the SAP S/4HANA system — execute arbitrary ABAP code or operating system commands, leading to loss of confidentiality, integrity and availability of data and the entire SAP environment.
Apply patches available from the vendor according to references — SAP Security Note 3694242 (https://me.sap.com/notes/3694242) published as part of SAP Security Patch Day. It is also recommended to restrict access to the RFC interface only to trusted hosts and audit accounts with administrator privileges.
SAP S/4HANA in Private Cloud and On-Premise variants; specific versions indicated in vendor references (SAP Security Note 3694242).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSap S\/4 Hana
APPSap102103104105106107108109
Related vulnerabilities
SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_...
VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617,...
Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be ...
Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an au...
Usługa OData aplikacji S4 HANA (Manage checkbook apps) — w wersjach 102, 103, 104, 105, 106, 107 — pozwala ata...