SAP security note 1593762, "Missing authorization check in JIT", is a program error note released on 12.07.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of JIT to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply manual steps and correction instructions attached in the note.
Reason and prerequisites
JIT does not contain authorization checks while changing the status of JIT calls in the JITE transaction. This may result in undesired system behavior.
References
Full note on SAP: SAP Support Launchpad note 1593762
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
