SAP Security Note
Medium priority
SAP security note 1575763, "Update #2 to Security Note 1523808", is a program error note released on 18.06.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
The correction instructions provided for the vulnerability (missing authorization checks in CATT / eCATT) addressed in Security Note 1523808 must be corrected for the following releases:
- SAP_BASIS 730
- SAP_BASIS 720
- SAP_BASIS 711
- SAP_BASIS 710
- SAP_BASIS 702
- SAP_BASIS 701
- SAP_BASIS 700
- SAP_BASIS 640
- SAP_BASIS 620
The corrected correction instructions have been added to this note.
Solution
Implement the correction instructions or import the relevant Support Packages as follows:
- SAP_BASIS 730 Support Package 03
- SAP_BASIS 720 Support Package 06
- SAP_BASIS 711 Support Package 08
- SAP_BASIS 710 Support Package 13
- SAP_BASIS 702 Support Package 08
- SAP_BASIS 701 Support Package 10
- SAP_BASIS 700 Support Package 25
- SAP_BASIS 640 Support Package 28
- SAP_BASIS 620 Support Package 70
Reason and prerequisites
CATT or eCATT does not contain authorization checks for checking an authenticated user’s authorization to access the function module CAT_CHECK_TABLE. Without these checks, a logged on user can simply call these functions. This may result in undesired change of the system behavior.
This note corrects an error during remote calls; this error caused the system to return misleading values in some cases when querying the user date format.
You must also refer to Notes 1523808 and 1562119 because these address the same topic.
References
- 1562119 – Update #1 to Security Note 1523808
- 1523808 – Missing authorization check in CATT or eCATT
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1575763
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
