SAP security note 1661157, "Missing authorization check in DISPATCH_SPML_REQUEST_BGRFC". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use the function module DISPATCH_SPML_REQUEST_BGRFC to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply the correction provided in this note.
Reason and prerequisites
The function module DISPATCH_SPML_REQUEST_BGRFC does not contain authorization checks for verifying an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.
References
- 1769046 – Update 1 to security note 1661157
- 1708665 – Function module with class-based exception, SNOTE
Affected components
- Basis Components > Security – Read KBA 2985997 for subcomponents > User Administration and Authorization administration
Full note on SAP: SAP Support Launchpad note 1661157
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
