Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization check for transaction calls in program, SAP security note 1462348

SAP Note 1462348
SAP Security Note

SAP security note 1462348, "Authorization check for transaction calls in program", was released on 12.01.2011. Below are the symptom and SAP recommended solution.

TypeSAP Security Note
StatusReleased for Customer
Released on12.01.2011

Description

Symptom

This security note addresses a vulnerability within the SAP Supplier Relationship Management (SRM) solution. The issue arises from missing authorization checks during dynamic calls to transactions from SRM programs, enabling potentially unauthorized users to access restricted SAP transactions at runtime.

Affected Releases: SAP SRM 4.0, SAP SRM 5.0, SAP SRM 6.0, SAP SRM 7.0, SAP SRM 7.01.

A malicious user could exploit this vulnerability to manipulate business logic, resulting in inconsistent data states, or violate regulatory compliance by gaining unprivileged access to critical business functions.

Solution

To mitigate this vulnerability, apply the relevant support packages or corrections as outlined below. Alternatively, implement the attached correction instructions available through the SAP Note.

References

Full note on SAP: SAP Support Launchpad note 1462348

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More