SAP security note 1572714, "Missing Authorization Check in Profile Parameter Handling", released on May 10, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functionality of Profile Maintenance to which access should be restricted. This can potentially result in an Escalation of Privileges.
Solution
Please apply the support package mentioned in this note at least, or the respective correction instruction.
Reason and prerequisites
The Profile Maintenance lacks permission checks for an authenticated user's authorization to access some of its functionality. This may result in undesired system behavior.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
References
This note refers to
- 1604594 – Digital Invoice Mexico: Authority Check PFL_GET_PARAMETER
- 1597294 – Note 1572714 cannot be implemented
- 1592494 – Information for implementing Note 1572714 in 640 and 700
- 1590102 – Runtime error AUTHORIZATION_MISSING in SAPLSUU1
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Referenced by
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
- 1604594 – Digital Invoice Mexico: Authority Check PFL_GET_PARAMETER
- 1597294 – Note 1572714 cannot be implemented
- 1592494 – Information for implementing Note 1572714 in 640 and 700
- 1590102 – Runtime error AUTHORIZATION_MISSING in SAPLSUU1
Affected components
- SAP_APPL 45B
- SAP_BASIS 46B to 46D, 610 to 730
Full note on SAP: SAP Support Launchpad note 1572714
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
