SAP security note 1497104, "Protect access to PSE files by additional AUTHORITY-CHECK", is a program error note released on 14.09.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
Insufficient authorization checks may allow ABAP programs to access PSE files.
Solution
Install the relevant kernel patch for your SAP release:
- Kernel 4.0B PL #1075 (or higher)
- Kernel 4.5B PL #1006 (or higher)
- Kernel 4.6D PL #2540 (or higher)
- Kernel 6.40 PL #342 (or higher)
- Kernel 7.00 PL #268 (or higher)
- Kernel 7.01 PL #106 (or higher)
- Kernel 7.10 PL #212 (or higher)
- Kernel 7.11 PL #098 (or higher)
- Kernel 7.20 PL #061 (or higher)
After applying the correction, the system will allow access to PSE files (i.e., files ending with .pse) and the file cred_v2 only after a successful authorization check for the object S_RZL_ADM with the field ACTVT and value 01, in addition to the S_DATASET and S_PATH authorization checks. These authorizations are included in the authorization proposals (see transaction SU24) for transaction STRUST.
CVSS
Score 0
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1497104
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



