SAP Security Note
High priority
SAP security note 1511041, "Missing Authorization Check in ECC-DIMP", is a note released on April 11, 2011. Below are the symptom and the SAP recommended solution.
Description
Symptom
There is a missing authorization check in the role SAP_SCM_INTEGRATION_DIMP. An authenticated user can access functionality that should be restricted, potentially leading to an escalation of privileges.
Unauthenticated or improperly authorized users could exploit this vulnerability to gain unauthorized access to sensitive functions within the ECC-DIMP component, leading to potential security breaches and data compromises.
Solution
To address this issue, you have two options:
- Implement the Support Package for ECC-DIMP: Ensure that the relevant support packages are applied.
- Execute Manual Correction Instructions: If applying the support package is not feasible, follow the manual steps to rectify the authorization checks.
Full note on SAP: SAP Support Launchpad note 1511041
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
