Note 1304803 reports can change transp requests? has anyone applied note?

Found the following notes
1304803 Security breach.  Certain reports that do not have authorization check can create or change transport requests  and change the piece list of a request
and
12988160 - Ability to execute undesired source code in the system using a special call of an RFC module (no further details as to what the 'undesired source code is'  has been defined)
Has anyone applied these notes? if so how do you check if the hole exists and then after the note has been applied how does one verify that the security breach has been corrected?
Please advsie
Maria

>
Maria Graziano wrote:
> Found the following notes
> 1304803 Security breach.  Certain reports that do not have authorization check can create or change transport requests  and change the piece list of a request
> and
> 12988160 - Ability to execute undesired source code in the system using a special call of an RFC module (no further details as to what the 'undesired source code is'  has been defined)
>
> Has anyone applied these notes? if so how do you check if the hole exists and then after the note has been applied how does one verify that the security breach has been corrected?
>
> Please advsie
>
> Maria
Via the corrections of the note, you will often be able to put the puzzle pieces together to be able to "test" whether it is corrected and how... The fact that there are sometimes follow-on notes to such program corrections is evidence of this. Some knowledge and creativity will be required for this.
If you want to be carefull of side affects (or find the guilty ones...) then try where-used-list look-ups on the objects being corrected to see where and how they are being used. Not 100% reliable because of dynamic coding techniques, but a good indicator for auditable development work...
Expressions such as "undesired source code" generally refer to remotely definable but internally executable source code, without appropriate checks in between.
If you cannot test it yourself and SAP releases the note as a "Security Note", then these are generally implementable without SAP standard consequences. If something in the z-custom world is bothered by it, you can normally be sure that you already have the problem "in da house"...
Cheers,
Julius

Similar Messages

  • Since converting my mobileme account into an icloud account, my free 5GB of storage has become a paid for extra 20GB without my requesting it. How can this happen, and has anyone else had this happen to them?

    Since converting my mobileme account into an icloud account, my free 5GB of storage has become a paid for extra 20GB without my requesting it. How can this happen, and has anyone else had this happen to them?

    To clarify: you are not being charged for the extra storage - it's complimentary to reflect the fact that you had storage in MobileMe. At the end of June it will disappear unless you care to pay to renew it.

  • HT1923 I cant update or remove itunes without receiving the message:  the install source (itunes.msi) for this product is not available. verify that the source exist and that you can access it.   Has anyone had this problem? Thanks

    I cant update or remove itunes without receiving the message:  the install source (itunes.msi) for this product is not available. verify that the source exist and that you can access it.   Has anyone had this problem? Thanks

    (1) Download the Windows Installer CleanUp utility installer file (msicuu2.exe) from the following Major Geeks page (use one of the links under the "DOWNLOAD LOCATIONS" thingy on the Major Geeks page):
    http://majorgeeks.com/download.php?det=4459
    (2) Doubleclick the msicuu2.exe file and follow the prompts to install the Windows Installer CleanUp utility. (If you're on a Windows Vista or Windows 7 system and you get a Code 800A0046 error message when doubleclicking the msicuu2.exe file, try instead right-clicking on the msicuu2.exe file and selecting "Run as administrator".)
    (3) In your Start menu click All Programs and then click Windows Install Clean Up. The Windows Installer CleanUp utility window appears, listing software that is currently installed on your computer.
    (4) In the list of programs that appears in CleanUp, select any iTunes entries and click "Remove", as per the following screenshot:
    (5) Quit out of CleanUp, restart the PC and try another iTunes install. Does it go through properly this time?

  • I would like to put Dreamweaver 8 on a new computer.  There is no "deactivate" function and the technical support person I chatted with recommended I come here.  Can I just use the serial number again?  How can I deactive?  Has anyone else run into this?

      There is no "deactivate" function and the technical support person I chatted with recommended I come here.  Can I just use the serial number again?  How can I deactive?  Has anyone else run into this?  How can I get Dreamweaver 8, which is no longer being activated by Adobe, on a new computer?  Is it even worth doing or do I need to get a new version.  What are the killer features I'm missing?

    If you manage to get it installed on your current OS, don't forget to install the 8.02 update.
    Adobe - Dreamweaver Support Center : Updaters
    Nancy O.

  • Has anyone applied pagination to a tree

    Has anyone applied pagination to a tree using jsf or any of its implementations... if yes how?
    thanks.

    Your model does not have a user-upgradeable SSD. You can check at OWC to see if they have replaceable SSDs for your model with instructions on how to install them. Note that this will void your warranty that has not yet expired.

  • CF9 and Ext JS - has anyone applied a different theme?

    Has anyone had any luck applying Ext JS themes to override the built-in theme that ships with CF 9? If so, which theme did you apply, where did you get it, and what was your method?
    My guess is that i can put any Ext JS 3.0 theme into my web site and then include the ext-all.css file and it should work. CF 8 allowed us to switch between themes (at least for some of the Ext JS functionality), which was cool because you could (in theory) add new themes on the server level and allow each of your applications to quickly choose. But this seems to be scrapped.
    Ideas?

    I was able to apply a different theme as follows:
    First, I downloaded one of these: (very simple modifications of the default CF theme)
    http://extjs.fudini.net/
    Then I used the csssrc attribute in cfajaximport to specify where I want CF to look for the styles. You will have to rearrange the folders of your downloaded extjs theme to be exactly like the one that ships with CF. Look at the documentation for cfajaximport.
    If you have control over your server, you could try putting new themes in the ColdFusion folder so they can be accessible by all your applications.
    If anyone knows how to find some really cool extjs themes, please share!

  • Has anyone applied Jan 2008 CPU yet?

    I patched all the nodes successfully, came to the post-installation instructions which said
    Select one node to execute the post installation steps. Follow the same set of instructions as mentioned in the Section 3.3.3, "Post Installation Instructions for a Non-RAC Environment".
    Users can continue to access the database during the post-installation steps.
    Now the script view_recompile_jan2008cpu.sql that has to be run
    1) cannot be run unless it is in startup upgrade mode
    2) I cannot open a node in startup upgrade mode while other nodes are open, makes sense
    What would you do?
    I took out the startup upgrade check out of the script but this was only a play system, I don't really want to do this to prod or to shut down all nodes just to start one in upgrade mode

    Users can continue to access the database during the post-installation steps.
    Now the script view_recompile_jan2008cpu.sql that has to be run
    1) cannot be run unless it is in startup upgrade mode
    2) I cannot open a node in startup upgrade mode while
    other nodes are open, makes sense
    As per readme
    You must recompile views for all databases except the following:
    * Databases created with Release 11.1.0.6 or later
    * Databases created with any release (for example, 10.2.0.3, 10.1.0.5, or 9.2.0.8) after CPUJan2008 or a later CPU has been applied
    So in above case Users can continue to access the RAC database during patching

  • How the status of certificate can change from Requested

    I have create new wallet.
    The certificate has status Requested.
    How can i change it to ready?
    What is the role of Certification Authority?
    Any one who have worked on ssl.
    Waiting for reply.
    Thanks to all.

    You have to export the requested certificate and have it signed by a Certifcate Authority. This can be the Oracle CA (part of 10g AS).
    Then use the signed certificate and import it.
    Afterwards you'll need to reconfigure the httpd.conf to use the wallet with the signed certificate.
    cu
    Andreas

  • When I get phone calls I can barely hear. Has anyone had this problem? I turned up the volume.

    I have a friend who bought the IPhone 6 and can barely her the person on the other end when they call.  She turned the volume up.  I can't think of what to do. Please help.

    Megster007,
    Let's boost the audio on your phone.  When did this issue begin? Have you powered off your phone and then on?  Do you have a case on your phone?
    EmmaM_VZW
    Follow us on Twitter @VZWSupport
    If my response answered your question please click the �Correct Answer� button under my response. This ensures others can benefit from our conversation. Thanks in advance for your help with this!!

  • My screen just went black.  I hear people calling me, but I can't answer.  Has anyone experienced this?

    My screen just went black.  I can't use the phone.  Anyone run into this?  Thanks for any advice.  I can't call Verizon!

        Hello Betty1011
    I don't want you to have the black screen of death! Let's get this fixed! Please try this and retest:http://bit.ly/SUCCgl I would also recommend this: http://vz.to/1c8GjOV
    Please let me know if this helps.
    JoeL_VZW
    Follow us on Twitter @VZWSupport

  • Can I change the request params in my backing bean?

    I want to change the request params in the backing bean method.
    For example:
    <h:commandLink value="test" action"myBean.test">
    <f:param name="a" value="1" />
    </h:commandLink>
    When user click the link, myBean.test() will be invoked.
    Can I change the request param values in myBean.test()?
    I mean, if I can change the value of "a" to "2" or add a new param?
    Thanks!

    I'm not sure if You can change any request parameters...
    You can set e.g. a request attribute in the case that You get the request object from the faces context and set the attribute.
    something like this...
    FacesContext fc = FacesContext.getCurrentInstance();
    HttpServletRequest req =    HttpServletRequest)fc.getExternalContext().getRequest();
    req.getParameter("id");
    req.setAttribute("id", new Integer(2));

  • Change the Request Field after it is submited

    Is it possible to change the Request after it is submited in Access Enforcer 5.2 ? Please advise.
    Thanks and let me know.
    Regards,
    PT.

    H PT,
    the approvers can change the requested roles in terms that they can deselect one or more roles at the stage they are responsible for.
    This deselection of a role could be justified when the ciombination of requested roles cause a risk.
    But once the request was created and sent you cannot change fields or so.
    Regards,
    Frank

  • Has anyone seen evidence of corrections being made to Maps?

    If it was just you, then it would be understandable because Apple might be swamped with requests to correct their Maps app and they might be attending to other users' requests first.
    That scenario would be awesome, because it would mean that there are corrections being made, even if they are not yours. But there is a problem. Everybody I've asked hasn't seen ANY corrections done. I hope this is not true.
    So.... the question is: Can we find evidence of any corrections at all? Even one correction?
    When we look at the millions... MILLIONS of user correction requests, has anyone seen a SINGLE correction done out of MILLIONS of requests.  Because ZERO out of MILLIONS of requests would be very bad.
    I want the Maps app to improve. I'm cheering Apple and supporting Apple. If the Maps app improves, then I would be happy and Apple users would be happy. The question is: has anyone seen any corrections??
    I'm hoping there are many examples out there of people seeing corrections.

    Hello,
    mybe one of the following Notes can help you:
    http://service.sap.com/sap/support/notes/1654940
    http://service.sap.com/sap/support/notes/1390097
    Regards
    -Seb.

  • Has anyone used Garageband on a new MBP?

    very interested in knowing the limitations. How many tracks of software instruments/loops can you get?
    Has anyone tried playing their songs made on a G5 Quad or hi end G5 ( with many effects and tracks) on the MPB? and what are the problems, limitations? Gliches?

    I use garageband all the time to record guitar tracks/vocal tracks. It really works great with my MBP. I use a presonus firebox with it too and all works really nicely; every once in awhile it will fall out of sync, but not much anymore. I've loaded up only about 7-9 tracks at any given time and it will play them all with no problem. The CPU usage graph doesn't even come close to getting pegged either! I found that better performance came when I chose the small buffer size. I think that if you plan on having ton of instruments at the same time, Garageband is probably not the way.
    So far I haven't found any limitations to Garageband. It does everything I want it to - record stuff. I haven't used a Quad or G5 with Garageband so I don't know if they would be faster/better. My MBP works great though.

  • Has anyone purchased songs to download then they aren't playable?

    There are a few songs that I've purchased in the last year that I can't play.
    Has anyone else had this problem? Is it fixable?
    Thanks,
    Rebecca

    Delete the broken copies and then redownload from your purchase history.
    tt2

Maybe you are looking for