Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update #2 to Security Note 1523808, SAP security note 1575763

SAP Note 1575763
SAP Security Note
Medium priority

SAP security note 1575763, "Update #2 to Security Note 1523808", is a program error note released on 18.06.2012. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Test Workbench > Testing Tools > eCATT Extended Computer Aided Test Tool
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on18.06.2012
LanguageEnglish

Description

Symptom

The correction instructions provided for the vulnerability (missing authorization checks in CATT / eCATT) addressed in Security Note 1523808 must be corrected for the following releases:

  • SAP_BASIS 730
  • SAP_BASIS 720
  • SAP_BASIS 711
  • SAP_BASIS 710
  • SAP_BASIS 702
  • SAP_BASIS 701
  • SAP_BASIS 700
  • SAP_BASIS 640
  • SAP_BASIS 620

The corrected correction instructions have been added to this note.

Solution

Implement the correction instructions or import the relevant Support Packages as follows:

  • SAP_BASIS 730 Support Package 03
  • SAP_BASIS 720 Support Package 06
  • SAP_BASIS 711 Support Package 08
  • SAP_BASIS 710 Support Package 13
  • SAP_BASIS 702 Support Package 08
  • SAP_BASIS 701 Support Package 10
  • SAP_BASIS 700 Support Package 25
  • SAP_BASIS 640 Support Package 28
  • SAP_BASIS 620 Support Package 70

Reason and prerequisites

CATT or eCATT does not contain authorization checks for checking an authenticated user’s authorization to access the function module CAT_CHECK_TABLE. Without these checks, a logged on user can simply call these functions. This may result in undesired change of the system behavior.

This note corrects an error during remote calls; this error caused the system to return misleading values in some cases when querying the user date format.

You must also refer to Notes 1523808 and 1562119 because these address the same topic.

References

Full note on SAP: SAP Support Launchpad note 1575763

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More