SAP security note 1657200, “Insufficient authorization check in AP-MD-PCA”, is a note released on April 10, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can exploit functions of AP-MD-PCA without proper authorization checks, potentially leading to an escalation of privileges. This vulnerability may result in undesired system behavior and poses a security risk to your SAP environment.
Solution
Implement this security note to apply the necessary authorization checks and mitigate the risk of privilege escalation.
CVSS
Score 4.0
Full note on SAP: SAP Support Launchpad note 1657200
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
