SAP security note 1592029, "Missing authorization check in customer master data". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of customer master data maintenance to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the attached correction.
Note: Transaction RWDEBRET is obsolete and its functionality is deactivated.
CVSS
Score 4.0 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N
References
Affected components
- SAP_APPL 40B
- SAP_APPL 45B
- SAP_APPL 46B
- SAP_APPL 46C
- SAP_APPL 470
- SAP_APPL 500
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
Full note on SAP: SAP Support Launchpad note 1592029
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
