SAP security note 1480248, "Missing Authorization Checks in Survey", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functionality of CRM Survey function module CRM_SVY_DB_SFA_LIST to which access should be restricted. This can potentially result in an Escalation of Privileges.
Solution
A new authority check with authorization object CRM_SVY, ID ACTVT, and FIELD 03 is introduced with this note. You have to check and possibly update the relevant authorization profiles for the affected users that use functionality of CRM Survey.
Reason and prerequisites
Function Module CRM_SVY_DB_SFA_LIST lacks permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.
CVSS
Score 0
References
- 1559411 – Authorization check in survey: no appropriate message
- 1509222 – Potential disclosure of persisted data: CRM_SVY_DB_SFA_READ
Affected components
- BBPCRM: From 701 To 701
Full note on SAP: SAP Support Launchpad note 1480248
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
