Advisory
A note with CVSS 6.0 for component BC-MID-RFC was released by SAP on 11.07.2023. The correction/advisory 3318850 was described with "[CVE-2023-35874] Improper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP Platform" and affects the system type Kernel.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is missing authentication check / improper authentication check within Kernel.
Risk specification
SAP NetWeaver Application Server ABAP and ABAP Platform, under some conditions, perform improper authentication checks for functionalities that require user identity.Solution
The correction implements the correct evaluation for value no of profile parameter rfc/allowoldticket4tt. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Note that this workaround is a temporary fix and is not a permanent solution: Set profile parameter rfc/allowoldticket4tt = both".
The advisory is valid for
- KERNEL 7.22 24
- KERNEL 7.53 36
- KERNEL 7.54 15
- KERNEL 7.77 34
- KERNEL 7.81 24
- KERNEL 7.85 25
- KERNEL 7.89 16
- KERNEL 7.92 5
- KERNEL 7.93 10
- KRNL64NUC 7.22 30
- KRNL64NUC 7.22EXT 30
- KRNL64UC 7.22 30
- KRNL64UC 7.22EXT 30
- KRNL64UC 7.53 36