SAP security note 1675605, “Missing authorization check in RTC”. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of the streaming server to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply the relevant patch from the "SP Patch Level" tab page in this note.
Reason and prerequisites
The streaming server application does not contain authorization checks for verifying an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
References
- 1670202 – Central Note for Portal Platform in SAP NW7.0 EhP2 SP12
- 1659047 – Central Note for Portal Platform in SAP NW7.0 EhP1 SP12
- 1653046 – Central Note for Portal Platform in SAP NW7.0 SP27
- 1587032 – Central Note for Portal Platform in SAP NetWeaver 04 SP29
Full note on SAP: SAP Support Launchpad note 1675605
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
