Description
Symptom 1
You use the role template S_RS_RDEMO or S_RS_ROPOP to set up roles. However, after you assign the roles, the users have no authorization for HybridProviders (S_RS_HYBR) or semantically partitioned InfoProviders (S_RS_LPOA).
Symptom 2
You use the role template “S_RS_RDEAD: BI role: BI Administrator (development system)”. The template gives the assigned users the authorization for all transactions (S_TCODE = “*”). This is not advisable for security reasons.
Available fix and Supported packages
- SAP_BW | 720 | 730
- SAP_BW 720 | SAPKW72003 |
Affected component
- BW-WHM-DST-AUT
Authorizations
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1432456