SAP Security Note
SAP security note 1462348, "Authorization check for transaction calls in program", was released on 12.01.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
This security note addresses a vulnerability within the SAP Supplier Relationship Management (SRM) solution. The issue arises from missing authorization checks during dynamic calls to transactions from SRM programs, enabling potentially unauthorized users to access restricted SAP transactions at runtime.
Affected Releases: SAP SRM 4.0, SAP SRM 5.0, SAP SRM 6.0, SAP SRM 7.0, SAP SRM 7.01.
A malicious user could exploit this vulnerability to manipulate business logic, resulting in inconsistent data states, or violate regulatory compliance by gaining unprivileged access to critical business functions.
Solution
To mitigate this vulnerability, apply the relevant support packages or corrections as outlined below. Alternatively, implement the attached correction instructions available through the SAP Note.
References
Full note on SAP: SAP Support Launchpad note 1462348
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
