SAP security note 1492428, "Missing Authorization Check in Organization Management", is released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functionality of Organization Management to which access should be restricted. This can potentially result in an escalation of privileges.
Solution
Import the corresponding support package or implement the attached correction instruction via SNOTE.
Reason and prerequisites
Program error.
CVSS
Score 0
Affected components
- SRM_SERVER 550 to 701
Full note on SAP: SAP Support Launchpad note 1492428
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



