Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in CATT or eCATT, SAP security note 1523808

SAP Note 1523808

SAP security note 1523808, “Missing authorization check in CATT or eCATT”, released on 17.02.2012. Below are the symptom, SAP recommended solution and the affected software components.

Released on17.02.2012

Description

Symptom

An authenticated user can use functions of CATT or eCATT to which access should be restricted. This may result in an escalation of privileges.

This security note has been updated. For more detailed information, see Security Note 1562119 and Security Note 1575763.

Solution

Implement the correction instructions or import the relevant Support Package.

References

Affected components

  • BC-TWB-TST-CAT: Basis Components > Test Workbench > Testing Tools > CATT Computer Aided Test Tool

Full note on SAP: SAP Support Launchpad note 1523808

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More