Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

RFC call cat_r2_tab_res without authorization, SAP security note 1520043

SAP Note 1520043

SAP security note 1520043, "RFC Call cat_r2_tab_res Without Authorization". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

This security note has been updated. For more detailed information, see Security Note 1585311.

An authenticated user can use functionality of the function module cat_r2_tab_res to which access should be restricted. This can potentially result in an escalation of privileges.

Solution

Import the correction instructions or the appropriate support package.

Reason and prerequisites

The function module cat_r2_tab_res lacks permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.

References

Affected components

  • Basis Components > Test Workbench > Testing Tools > CATT Computer Aided Test Tool (BC-TWB-TST-CAT)
  • SAP_APPL 31I to 31I
  • SAP_APPL 40A to 40B
  • SAP_APPL 45A to 45B
  • SAP_BASIS 46A to 46D, 610 to 640, 700 to 702, 710 to 730

Full note on SAP: SAP Support Launchpad note 1520043

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More