SAP security note 1675432, "Missing authorization checks in CA-CL". Below are the symptom and the SAP recommended solution.
Description
Symptom
An authenticated user can access CA-CL functions of to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the correction instructions.
Reason and prerequisites
CA-CL does not contain authorization checks for checking an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 7.5 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:C
Full note on SAP: SAP Support Launchpad note 1675432
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
