SAP security note 1466156, "Missing Authorization Check in a BTE application", is a program error note released on 08.06.2010. Below are the symptom, SAP recommended solution and affected software components.
Description
Symptom
An authenticated user can use functionality of a BTE application to which access should be restricted. This can potentially result in an escalation of privileges. In this case, a deactivation of an application is possible without the corresponding authorization for activating it.
Solution
Please implement the attached correction instruction in your system.
Reason and prerequisites
A BTE application lacks permission checks for an authenticated user's authorization to access some of its functionality. This may result in undesired system behavior.
References
This note refers to
Affected components
- SAP_ABA 620
- SAP_ABA 640
- SAP_ABA 700 to 702
- SAP_ABA 710 to 711
Full note on SAP: SAP Support Launchpad note 1466156
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
