Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization Check in SW-Delivery tools, SAP security note 1493911

SAP Note 1493911Medium priority

SAP security note 1493911, “Missing Authorization Check in SW-Delivery tools”, is a note released on December 14, 2010. Below is the security information published by SAP for this note.

PriorityCorrection with medium priority
StatusReleased for Customer
Released onDecember 14, 2010

Description

An authenticated user can exploit missing authorization checks in transport and SW-delivery tools, potentially leading to an escalation of privileges. This vulnerability allows unauthorized access to restricted functionalities and read access to several database tables if the user has execution permissions for reports and function modules.

Affected components

  • Basis Components > Upgrade – general (BC-UPG)
  • SAP_APPL: 45B
  • SAP_BASIS: 46B to 46D, 610 to 640, 700 to 702, 710 to 730, 72L

Solution

Import the relevant Support Package. The corrections are designed to integrate seamlessly with existing application functions, requiring no additional adjustments or configurations as they involve SAP-internal functionality.

Additional information

  • Released On: December 14, 2010
  • Priority: Correction with medium priority
  • Status: Released for Customer

References

Full note on SAP: SAP Support Launchpad note 1493911

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More