SAP security note 1472367, "Security fix for missing authority check for call transactio", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Due to a vulnerability in SRM, it is possible for a hacker to perform unauthorized actions without the knowledge of the logged-in user.
Solution
Implement the authority check before the call transaction to resolve the issue. Please apply the attached correction instruction to prevent malicious users from performing vulnerable activities.
Reason and prerequisites
The symptom is caused by the missing authorization check in the code.
CVSS
Score 0
Affected components
- SRM_SERVER (500, 550, 600, 700, 701)
- BBPCRM (400)
Full note on SAP: SAP Support Launchpad note 1472367
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
