SAP security note 1493911, “Missing Authorization Check in SW-Delivery tools”, is a note released on December 14, 2010. Below is the security information published by SAP for this note.
Description
An authenticated user can exploit missing authorization checks in transport and SW-delivery tools, potentially leading to an escalation of privileges. This vulnerability allows unauthorized access to restricted functionalities and read access to several database tables if the user has execution permissions for reports and function modules.
Affected components
- Basis Components > Upgrade – general (BC-UPG)
- SAP_APPL: 45B
- SAP_BASIS: 46B to 46D, 610 to 640, 700 to 702, 710 to 730, 72L
Solution
Import the relevant Support Package. The corrections are designed to integrate seamlessly with existing application functions, requiring no additional adjustments or configurations as they involve SAP-internal functionality.
Additional information
- Released On: December 14, 2010
- Priority: Correction with medium priority
- Status: Released for Customer
References
Full note on SAP: SAP Support Launchpad note 1493911
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
