SAP Security Note
HotNews
SAP security note 1304803, "Security note: Changing a transport without authorization", is released on 24.07.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
Certain reports that do not have an authorization check can create or change transport requests and change the piece list of a request. This is a security breach.
Solution
Use the Note Assistant to implement the correction instructions or import the relevant Support Package.
If the report TH_E070E also exists in your system, delete it manually. For technical reasons, we cannot provide general correction instructions for this report. If the package STRW does not exist in your system, you must first call transaction SE03 -> "Change Object Directory Entries" and change the package from R3TR PROG TH_E070E to SDEL.
In this case, the package change must be transported together with the deletion of the report.
The correction does not influence the normal functioning of the Transport Organizer (transactions SE01, SE09, or SE10) or other applications. The Transport Organizer does not use the reports in any way.
We strongly recommend that you implement this note to eliminate this security flaw.
Reason and prerequisites
This problem is caused by a delivery error.
References
Full note on SAP: SAP Support Launchpad note 1304803
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
