Tech Alert: Major Security Alert for All SAP ABAP Platforms

Written by Mark Mergaerts in Technology


On 8 June SAP has issued note 3007182 - [CVE-2021-27610] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform, describing a major vulnerability in the handling of incoming RFC an HTTP requests. The issue affects all ABAP systems, including SAP NetWeaver ABAP, SAP S/4HANA and SAP BW/4HANA, regardless of version. The issue has a CVSS Base Score of 9/10, which is Critical.

Shutterstock 732366031 1

The cause of the vulnerability is that the ABAP server does not make an unambiguous distinction between incoming RFC/HTTP requests from inside the system or from an external caller. This could be exploited by malicious users to obtain illegitimate access to the SAP ABAP system. There is no workaround except to strengthen network protection against external RFC and HTTP communication to SAP. However, SAP provides a software correction, which consists of:

  1. New kernel version for kernels 7.21, 721_EXT, 7.22, 7.22_EXT, 7.22_EX2, 7.49, 7.53, 7.77 and 7.81
  2. Correction to SAP_BASIS component to be implemented with Transaction SNOTE; applicable to all systems on SAP_BASIS 7.00 and higher

Considering the criticality of the problem our advice is to apply this correction as soon as possible, but still in an organized manner whereby you patch the non-production systems first. The scope of the SNOTE correction is small (changes just one class), so it may be feasible to move it to production relatively fast. With the kernel you need to be more careful and plan at least a minimum period during which the non-production systems operate on the new kernel version. You should also consult the specific kernel regression note (see SAP note 1802333 for general information about kernel regressions). For the kernel levels advised in note 3007182, the regression notes are listed in the table below.

Tabel tech alert

The Expertum consultants are available to address your questions and to assist you with the solution.

We're here to listen.
Get in touch with us.

About the author

Mark Mergaerts

Mark Mergaerts has more than 25 years of experience in SAP Basis Consulting. He knows the ins and outs of databases and landscapes and is highly experienced in performance and tuning of ABAP systems and the adapting of customer code when migrating to a different database platform.

Read more articles by Mark Mergaerts

Related articles