SAP Security Note
High priority
SAP security note 1576764, “Missing authorization check in Task Handler”, released on September 13, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can utilize functions of the Task Handler to which access should be restricted. This may result in an escalation of privileges.
Solution
The correction includes a central solution in the kernel and ABAP changes based on the kernel solution. Applying the appropriate kernel patch level mentioned in this note is mandatory.
CVSS
Score 4.9 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:P
Affected components
- SAP_APPL (Versions 31I, 40B, 45B)
- SAP_BASIS (Versions 46B to 730)
- KERNEL (Various versions including 4.6D, 6.40, 7.00, 7.10, 7.20)
Full note on SAP: SAP Support Launchpad note 1576764
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
