SAP security note 1515699, "Missing authorization check at call transaction //rrp4/5", is a note. Below are the symptom and the SAP recommended solution.
Description
Symptom
An authenticated user can use the functionality of transaction /SAPAPO/RRP4 and /SAPAPO/RRP5 to which access should be restricted. This can potentially result in an escalation of privileges.
Solution
- Implement the attached correction instructions.
- Alternatively, import the relevant Support Package for your release.
Reason and prerequisites
There is a lack of permission checks for an authenticated user’s authorization to access some of the functionalities. This may result in undesired system behavior. Prerequisite: Implementing this note requires Note 1429098.
References
Full note on SAP: SAP Support Launchpad note 1515699
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



